Configuring AI governance policy is the easier half of the job. Setting up a Block rule, a Redact rule, a Warning- that's a decision an admin can make in the platform in a few clicks. The harder half is what happens next: proving those rules are actually firing, on the endpoints they're meant to protect, against the users they're meant to govern.

Until now, Darwin's Audit Log captured configuration events, ruleset changes, logins, requests, alerts, but not the enforcement itself. An admin could see that a rule existed. They couldn't see the rule operating. When an employee reported that ChatGPT stopped working, IT had no way to answer the first question they needed to answer: is this Darwin, or something else? Every ticket became a Darwin support escalation. Every move from Monitor to Govern mode became a leap of faith.

Darwin's Activity Log closes that gap. Every enforcement action the agent takes, every block, every redaction, every warning, is now recorded with full context: the tool, the endpoint, the user, the rule that fired, and exactly why it matched.

Activity Log—every enforcement action Darwin takes, recorded with the rule, endpoint, and user behind it.

Every Enforcement Action, Recorded Row by Row

Activity Log lives as a new tab in AI Control Center. Every entry captures the full context of what Darwin's agent did: the AI tool and domain accessed, the endpoint the action ran on, the timestamp, the action taken (Block, Redact, or Warning), the rule that triggered it, the details on why the rule matched, the end user affected, and a link to the related alert if one was generated.

Where a single rule produces more than one action; for example, a Block plus a Warning, each is logged as its own consecutive entry rather than merged into a single row. Related detections like Shadow User Detected and Secondary Redirection appear as their own entries too. What Darwin did is what the log shows, in exactly the granularity it happened.

Built for Narrowing, Not Browsing

Enforcement generates volume. A live Darwin deployment can produce thousands of enforcement events a day, so Activity Log is built for the reality of finding one specific answer inside that volume. Admins can filter by action, tool, rule, department, and match details. Time ranges narrow down to minute and hour resolution. An "alert-generating only" toggle strips the view to events that crossed an alerting threshold. Endpoint search finds a single machine in one query.

Every filtered view exports to CSV, so a compliance review or a targeted investigation moves from a filtered lookup to a shareable record in seconds.

From Configuration to Confidence

For many agencies, the leap from Monitor mode to Govern mode has been the hardest step in AI governance. Turning on enforcement means turning on real consequences for end users, and until now, doing so without visibility into what the agent is actually doing has meant flying blind. When something breaks, the ticket comes to the security team. When the security team can't confirm what happened, the ticket comes to Darwin.

Activity Log changes that operational reality. Before extending enforcement across the organization, admins can turn on a rule, watch it fire against the right endpoints, and confirm it's operating as designed. When an end user reports that a tool stopped working, IT can search the endpoint name, narrow to the reported window, and read the Action and Rule columns. If no entry exists in that window, the issue isn't Darwin, and IT resolves it internally without an escalation.

The Complete Audit Trail

Governance evidence has two halves: what the organization configured, and what actually happened as a result. Audit Log has always covered the first half: every ruleset change, every login, every configuration event. Activity Log now covers the second half: every enforcement action Darwin's agent took on every endpoint.

Together, they close the audit trail. Compliance officers can pull configuration history and enforcement history side by side, producing evidence that isn't just what the policy said, but what the policy did.

Built for the Way Security and IT Teams Actually Work

State and local government agencies moving to active AI enforcement need more than a policy that exists on paper. They need proof that it's operating in production, on every endpoint, against every user. Darwin's Activity Log gives IT, security, and compliance teams the observability to move from configuring AI governance to operating it, with enforcement that's verifiable, defensible in an audit, and supportable by their own team.

Ready to see Activity Log in action? Book a demo or reach out to your Darwin AI contact to get a walkthrough.

Interested in Learning More?