OpenSSF Finding and Fixing Vulnerabilities Using AI

4.4 Preparing AI logging

Mechanisms may fail, or you may want to later determine what did or did not happen. Therefore, enable logging of AI system activity, and log it in a way that the AI can’t delete or modify earlier log messages. These logs should record what the user requested and what the AI-enabled system did and replied. These logs enable detection, response, and recovery if something should go wrong.

Individuals will often choose to have their harness or sandboxing system store logs in a directory that the AI itself cannot normally read or write. Organizations may want to have those logs sent to a separate system (like all other logs) so that even subversion or destruction of the original system cannot erase the log entries. Protect the logs from unauthorized viewing; they may contain sensitive information.

Most AI systems have some form of logging. For example, by default Claude Code records transcripts in ~/.claude/ for 30 days. By default, the nono tool logs sandbox-relevant runtime operations, tool calls, mediated decisions, and capability or path access denials into a local, cryptographically verifiable session audit trail. That said, you may want to enable more logging or change what it does.

Examine your logging configuration and adjust it early, before using the system seriously. You can change the logging configuration, but you can’t retroactively change the logging configuration for past events. If you might want to review some data later, make sure it’s recorded.