What you will build
A minimal evidence packet with explicit coverage gaps. It should let another engineer understand what happened without collecting every prompt, source file and credential.
- Action and correlation ID
- Local execution evidence
- Governed audit metadata
- Redacted retained record
Conceptual flow. Follow the lesson for prerequisites, exact commands and verification limits.
Read the mechanism
Different logs answer different questions. A test runner records assertions and exit status. A proxy log records a network decision. An agent transcript records what the agent said. Organization audit records have their own schema and prerequisites; none is a universal substitute for the others.
Docker AI Governance audit logging requires its license and enforced organization governance for local sandboxes. The documented local support begins at v0.39.0. Hosted storage of those audit records does not imply audit coverage for cloud sandboxes.
Audit metadata intentionally excludes details such as full prompts and tool arguments. This can be useful for privacy, but it limits replay and forensic conclusions. A claim such as “we can reproduce everything the agent did” needs much more evidence than an audit event list.
Worked lab · one harmless denial
Reuse a disposable network lab with a known scoped deny. Perform one bounded synthetic request, then inspect a limited log window:
sbx policy log handbook-net --limit 20 --json
If that earlier sandbox has been removed, create a new authorized exercise from chapter 9 rather than assuming its logs or identity still exist.
Build an evidence index:
{
"runId": "synthetic-lab-001",
"inputRevision": "record actual revision",
"sandboxIdentity": "record actual identity",
"policyRevision": "record actual policy",
"artifacts": {
"processResult": "redacted command result",
"policyDecision": "matching decision record",
"auditRecord": null
},
"auditGap": "not available without entitled governed environment"
}
In an entitled environment, correlate a finalized audit JSONL record with the session and denial using supported fields. Do not ingest temporary files as completed evidence. Define who may read the packet and how long it is retained.
Expected observations
The network log should explain the applicable decision for that destination. It cannot prove that every local file read was recorded. The current policy-log reference does not support filesystem log output, so do not advertise it as a complete filesystem audit.
An absent audit record can mean the feature was not enabled, the event is outside coverage, collection is incomplete or the correlation is wrong. Record the uncertainty instead of inferring that nothing happened.
Troubleshooting
Check license, enforced governance, installed version and event coverage before diagnosing an absent record. Check clock and correlation identifiers before joining logs. Redact tokens and unnecessary user data before sharing evidence.
Treat stdout and stderr as untrusted, potentially sensitive input. An agent or program can print misleading “success” text; the collector should preserve exit status independently.
Interview practice
What does a policy-denial log establish?
It supports that a specific request met a particular enforcement decision. It does not establish the absence of every alternative path or reproduce all guest execution.
Why collect less rather than every payload?
Useful evidence needs deliberate coverage, retention and access control. Unbounded collection increases privacy and secret exposure while making analysis harder.
Completion check
For every artifact in your packet, state what it proves, what it omits and who can access it. Mark unavailable enterprise evidence explicitly.
Sources and version notes
Checked 6 October 2026; current baseline: sbx v0.46.0. AI Governance Audit Logs · Local audit logs · sbx policy log
Make the understanding yours.
Use the completion check above. Mark this chapter when you can explain the mechanism and its limits.
Self-assessed reading progress. This does not certify that a lab ran or a system is secure.