Dd Audit Ai Activity

作者 datadog-labs5b40c73824ec無授權條款177 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新

Audit what the Bits AI assistant (MCP server) has done in your Datadog org — tool calls by user, resources accessed, and anomaly flags for AI governance.

AI 產生的概覽

透過 Audit Trail 稽核 Datadog Bits AI 的 MCP 工具活動,呈現使用者、動作、資源與異常標記。

功能
此技能提供一組 Datadog Audit Trail 查詢,用來呈現 Bits AI 助理(MCP 伺服器)在組織中做過哪些事。它會報告依使用者區分的工具呼叫、執行的動作、受影響的資源類型與 ID、用戶端 IP 與國家,並產出包含總量、活躍使用者、動作分布與資源類型的每週摘要。它也會列出異常訊號,例如破壞性 AI 動作、支援使用者活動、首次使用的使用者、高頻呼叫,以及超出範圍的資源存取,並定義稽核報告的文字輸出格式。
適用情境
適用於對 AI 動作進行安全審查、需要 AI 活動可被記錄並歸屬於特定使用者的合規稽核,以及關於 AI 助理採用情況與風險面的治理報告。當你需要知道哪些使用者呼叫了 Datadog AI 助理,以及它變更了什麼時,適合使用。
執行需求
需要可存取 Datadog 的 pup CLI,透過 pup auth login(OAuth2)或具備 audit_logs_read 權限的 DD_API_KEY 與 DD_APP_KEY 進行驗證,並使用 jq 處理 JSON 管線。需要連線至 Datadog Audit Trail 的網路存取。此技能不附帶指令碼,僅為說明與 shell 查詢。

Audit Trail: AI Activity Audit

Every Datadog MCP tool call is recorded in Audit Trail under the Bits AI SRE category. This skill surfaces what the AI assistant has done in your org — which users invoked it, which tools were called, and which resources were affected.

Prerequisites

bash
pup auth login   # OAuth2 (recommended)# or set DD_API_KEY + DD_APP_KEY with audit_logs_read scope

Queries

All MCP tool activity in a time window

bash
pup audit-logs search --query "@evt.name:\"MCP Server\"" --from 7d --limit 500 -o json \  | jq '[.data[] | {      timestamp: .attributes.timestamp,      user: .attributes.attributes.usr.email,      actor_type: .attributes.attributes.evt.actor.type,      action: .attributes.attributes.action,      resource_type: .attributes.attributes.asset.type,      resource_id: .attributes.attributes.asset.id,      ip: .attributes.attributes.network.client.ip,      country: .attributes.attributes.network.client.geoip.country.name    }]'

Activity by user (who is using the AI assistant most?)

bash
pup audit-logs search --query "@evt.name:\"MCP Server\"" --from 30d --limit 1000 -o json \  | jq '[.data[] | .attributes.attributes.usr.email]    | group_by(.)    | map({user: .[0], tool_calls: length})    | sort_by(-.tool_calls)'

Resources modified by AI tool calls

bash
pup audit-logs search \  --query "@evt.name:\"MCP Server\" @action:(created OR modified OR deleted)" \  --from 7d --limit 500 -o json \  | jq '[.data[] | {      timestamp: .attributes.timestamp,      user: .attributes.attributes.usr.email,      action: .attributes.attributes.action,      resource_type: .attributes.attributes.asset.type,      resource_id: .attributes.attributes.asset.id    }]'

AI activity for a specific user

bash
pup audit-logs search \  --query "@evt.name:\"MCP Server\" @usr.email:[email protected]" \  --from 30d --limit 500 -o json \  | jq '[.data[] | {      timestamp: .attributes.timestamp,      action: .attributes.attributes.action,      resource_type: .attributes.attributes.asset.type,      resource_id: .attributes.attributes.asset.id    }]'

Weekly summary report

bash
pup audit-logs search --query "@evt.name:\"MCP Server\"" --from 7d --limit 1000 -o json \  | jq '{      total_tool_calls: (.data | length),      unique_users: ([.data[] | .attributes.attributes.usr.email] | unique | length),      top_users: (        [.data[] | .attributes.attributes.usr.email]        | group_by(.)        | map({user: .[0], calls: length})        | sort_by(-.calls)        | .[:5]      ),      actions_breakdown: (        [.data[] | .attributes.attributes.action]        | group_by(.)        | map({action: .[0], count: length})        | sort_by(-.count)      ),      resource_types: (        [.data[] | .attributes.attributes.asset.type]        | group_by(.)        | map({type: .[0], count: length})        | sort_by(-.count)      )    }'

Anomaly Flags

SignalGovernance concern
AI performing deleted actions on monitors or dashboardsReview whether destructive AI operations are expected
AI acting as SUPPORT_USERDatadog support using AI on behalf of org
First-time user invoking AI toolsNew user accessing AI assistant
High volume of tool calls in short windowAutomated/batch AI usage
AI accessing resources outside user's normal scopePotential over-permissioned AI session

Output Format

AI Activity Audit — [Org] — [Date Range]
Total MCP tool calls: [N]Unique users: [N]
Top users:  [[email protected]]: [N] calls
Actions breakdown:  accessed: [N]  modified: [N]  created: [N]  deleted: [N]
Resource types affected:  dashboard: [N]  monitor: [N]
Anomalies:  [List any flagged events with timestamp, user, action, resource]

Context

This skill is most useful for:

  • Security reviews: Verifying AI actions were authorized and within expected scope
  • Compliance audits: Demonstrating AI activity is logged and attributable to specific users
  • Governance reports: Understanding adoption and risk surface of the AI assistant across the org

No other observability vendor audits their AI assistant's actions at this level of detail.

References

來源與署名

來源:datadog-labs/agent-skills位於dd-audit/ai-activity-audit提交5b40c73

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架