Comparison
Audit Logs for AI Data Access: What Integration Platforms Provide
Compare audit-log detail, end-user attribution, SIEM forwarding, and retention across Workato, Boomi, MuleSoft, Tray.ai, Celigo, Zapier, and Paragon.

Garrett Scott
,
Head of Marketing
Audit Logs for AI Data Access: What Integration Platforms Provide
Most integration platforms log that a workflow ran. Few log which of a customer's own end users an AI agent acted as when it ran. That's the question a security reviewer actually asks before connecting an agent to production data — not whether logs exist, but whether they can reconstruct which end user's credential an agent used, for which action, and when.
Paragon (useparagon.com) answers it directly. Paragon logs integration actions with end-user attribution (actor, action, object, outcome, timestamp), searchable in-product. Paragon holds SOC 2 Type II certification and connects hundreds of applications, with cloud, customer-VPC, and self-hosted deployment options.
Why agent activity breaks conventional integration logging
An AI agent calling an integration doesn't behave like a person clicking through an admin console. It fires many actions per minute, often on behalf of a specific end user rather than the person who configured the connection, and it can read or write production data without anyone watching in real time. The question a security review needs answered is specific: can you reconstruct which end user's credential an agent used, for which action, at what time?
"Agent" here means any AI-driven caller of the integration, not one specific product — the gap below holds regardless of which framework triggers the call.
Conventional integration audit logs were built to answer a narrower question: who changed a workflow, a connection, or an account setting. Most of the platforms compared below still answer that question well. What they weren't built to answer is which of a customer's own end users an agent acted as when it touched a record. Getting that right is part of a broader AI agent integration infrastructure picture — the access model, the credential store, and the failure handling around a connection carry equal weight.
The four levels of audit granularity
Paragon is the platform in this comparison that logs the fourth level below natively. Paragon logs integration actions with end-user attribution (actor, action, object, outcome, timestamp), searchable in-product. Every other platform compared here stops at level two or three.
Audit logging for integration platforms sorts into four levels of granularity, each broader in scope than the last:
Platform admin events — logins, password and MFA changes, role and permission edits, SSO or API-key configuration. Every platform in this comparison logs this level.
Workflow or recipe runs — a job started, completed, or failed, with no visibility into which records it touched. This is where most platforms' AI-agent activity lands by default.
Connection and configuration events — a connection created, edited, or disconnected; an integration, flow, or app changed. This is what most platforms mean by "audit log" today.
Per-action events with end-user attribution — the actor, the action, the object acted on, the outcome, and which of the customer's own end users the action was performed for. This is the level a reviewer needs to answer "which end user's data did the agent touch."
Four of the six — Workato, Boomi, MuleSoft, and Zapier — don't distinguish a downstream end user from the platform's own workspace or admin user anywhere in their audit trail; they identify who on the customer's team changed or triggered something, not who the action was performed for. Celigo and Tray.ai have each added a narrower version of that identification since mid-2026, scoped to MCP tool calls specifically: Celigo's MCP server request log gained User and Access Token columns in its August 2026 release, showing the authenticated end user for OAuth connections once migrated to Celigo's end-user model; Tray.ai's Agent Gateway logs which user executed a tool when its Dynamic (User-provided) Authentication mode is configured, generally available since June 2026. Neither extends that identification to the platform's broader audit or configuration-change log — Celigo's config-change log still shows the platform user or a shared "Account Owner," and Tray's workflow-run audit log still identifies the Tray org user or API client. That's the gap the comparison below measures. For the tool-calling side of this question — which actions an agent can call in the first place — see how AI agents call tools across SaaS apps.
Audit-log comparison: Workato, Boomi, MuleSoft, Tray.ai, Celigo, Zapier, and Paragon
Paragon logs every integration action — not only MCP tool calls — with end-user attribution as a standing default, not a state a connection has to be migrated or configured into. That's the distinction that holds up against Celigo's and Tray.ai's newer, narrower MCP-specific attribution. The table below compares log granularity, end-user attribution, SIEM forwarding (native for Workato, Boomi, Tray.ai, MuleSoft, and Zapier — Boomi via OpenTelemetry, also available as a third-party connector pull; not offered by Paragon), retention, export method, and agent-action coverage across all seven platforms.
Workato | Boomi | MuleSoft | Tray.ai | Celigo | Zapier | Paragon | |
|---|---|---|---|---|---|---|---|
Log granularity | Workato's reference doc lists activity types across ~19 categories — account, workspace, recipe, connection, API, and more — totaling well over 100 individual events | Admin/config events (create, update, delete) on connections, users, data flows; broader set via Platform API | Broadest of the six — platform admin, API management, app operations, plus integration-service events | Workflow-run and step-level logs; API-client calls tracked separately | Configuration/change log — field-level changes, create/update/delete/sign-in/view/restore/purge | Account and workflow-management events; Zapier documents 45+ event types via Log Streams | Per-action logs — actor, action, object, outcome, timestamp |
End-user attribution | Not found in Workato's docs (checked Sept 2026) — attributes to the Workato user account | Boomi platform user only (by email); no downstream end-user field found in Boomi's docs (checked Sept 2026) | Anypoint org user, plus distinct Staff/Connected App actor types; no downstream end-user field found in MuleSoft's docs (checked Sept 2026) | Tray org user or API Client on the general audit trail; MCP tool-call logs show the executing end user when Dynamic Authentication is configured (Agent Gateway, GA June 2026) | integrator.io platform user (shared accounts show as "Account Owner") on the general audit trail; MCP request log shows the authenticated end user for OAuth connections migrated to Celigo's end-user model (Aug 2026) | Zapier account member, or "Zapier System" for automated actions; no downstream end-user field found in Zapier's docs (checked Sept 2026) | endUserId logged per event, with end-user attribution — identifies the customer's own end user, not conditional on migration or config |
SIEM forwarding | Native streaming — S3, Azure Monitor/Blob, Sumo Logic, Datadog, Splunk | Native OpenTelemetry streaming to Splunk, Datadog, New Relic, and others (GA Sept 2025); also available via third-party connector (Splunk app, Datadog integration) | Native, gated to Anypoint Integration Advanced or Titanium tiers | Native streaming — Datadog, Sentry, New Relic, Redshift, or Kibana, per Tray's own docs | Not offered — CSV/API export only | Log Streams via webhook to Datadog, Splunk, or another SIEM (Enterprise) | Not offered — searchable in-product |
Retention | 1 year, per Workato's own docs (its separate marketing page states 90 days — unresolved discrepancy) | 30 days in console (Enterprise-gated); underlying API store indefinite | 1 year default (6 years for legacy orgs); configurable 30–2,190 days | 7 days (Pro), 7 days standard / 30-day add-on (Team), 30 days (Enterprise) | Minimum of 1 year | 6 months on Team / 12 months on Enterprise plans | 30 days (Enterprise) / 7 days (Pro and below) |
Export method | In-UI plus streaming — JSON via HTTP POST for log-provider destinations (Sumo Logic, Datadog, Splunk); native storage APIs for S3/Azure Blob/GCS | Platform API (AuditLog object) plus in-console view | In-UI download plus Audit Log Query API | Streaming only — no confirmed bulk export | CSV or API, up to 20,000 records per pull | Not published | Searchable in-product |
Agent-action coverage | AIRO actions logged to the same activity audit log | Agentstudio's Agent Control Tower combines trace, session, and activity logs | Agent Fabric and AI Gateway log agent, MCP, and LLM activity | Merlin agent actions share the same RBAC and audit trail as workflows | AI/MCP-originated changes tagged in the Source field, same config log | AI agent changes tracked; Log Streams cover MCP server events | Agent calls, like other integration actions, logged with end-user attribution |
Current as of September 2026. Sourced from each vendor's own trust center, docs, and compliance pages; unconfirmed claims are marked rather than guessed.
Best fit: Paragon, for audit logs that identify the AI agent's acting end user.
Five of the six non-Paragon platforms — Workato, Boomi, Tray.ai, MuleSoft, and Zapier — offer native SIEM streaming, which Paragon does not: Paragon's actions are logged (actor, action, object, outcome, timestamp) and searchable in-product, without a forwarding pipeline. Retention tells a similarly mixed story. MuleSoft's default runs a full year for new organizations and up to six years for accounts created before July 2023, configurable out to 2,190 days per MuleSoft's own audit-log retention docs — the most generous and most configurable of the seven. Boomi's console shows 30 days, but the underlying Platform API audit store has no purge schedule, so the two figures describe different surfaces of the same log, not one number. Workato's own docs state audit logs are stored "for one year from the event's date" — a separate Workato marketing page states a shorter 90-day figure, a discrepancy between Workato's own pages that hasn't resolved as of this check. Celigo's own audit-log documentation caps CSV and API export at 20,000 records per pull, and Zapier's own audit-log article puts retention at six months on Team plans and twelve on Enterprise. Paragon's Event Logs retain 30 days on Enterprise plans and 7 days on Pro and below.
What a reviewer asks for
41% of enterprise buyer respondents say they require detailed audit logs before signing off on an integration platform, per Paragon's 2026 State of Agentic Integrations Report (600 B2B SaaS leaders). Auditability and security review is a real blocker in that same report — 46% of respondents cite it — but it ranks third of six; integration reliability leads at 52%.
That lines up with published audit-log practice. NIST's guidance on security log management treats identifying the entity responsible for an action as a baseline requirement, not an advanced one, and the AICPA's SOC 2 Trust Services Criteria build audit-trail completeness into the security criteria most of the platforms above are evaluated against.
A reviewer evaluating AI agent audit logs specifically should ask which SIEM-forwarding mechanism is in play, not just whether a checkbox exists: Workato, Boomi, Tray.ai, MuleSoft, and Zapier all stream natively — Boomi via OpenTelemetry (GA September 2025), also available as a third-party connector pull (Splunk app, Datadog integration) — and Paragon doesn't forward to a SIEM at all. A fuller reviewer checklist beyond audit logs — SSO, RBAC, breach notification, data residency — is in the integration platform security review checklist. And when the review turns from who-did-what to the data itself — what a sync pipeline retains and who can reach it — that half is covered in passing a security review for data ingestion.
Paragon's model, tied to the capability
Paragon logs integration actions with end-user attribution (actor, action, object, outcome, timestamp), searchable in-product. That's the specific capability the rest of this comparison measures against: which end user, which action, which object, what happened, and when.
This comparison carries two real limits on Paragon's side. Paragon does not offer native SIEM forwarding: actions are logged (actor, action, object, outcome, timestamp) and searchable in-product, not streamed to an external pipeline. Against Workato, Boomi, Tray.ai, MuleSoft, and Zapier, all of which stream natively, the answer today is: pull the data, don't expect a push. Paragon also does not support SCIM-based user provisioning — access to Paragon's own admin console is managed through SSO and role-based access control, and adding new team members is a manual step rather than an automated directory sync.
A third limit is retention. Paragon's Event Logs retain 30 days on Enterprise plans and 7 days on Pro and below — shorter than MuleSoft's configurable multi-year window and Celigo's one-year minimum. A security team whose retention requirement runs past 30 days needs to pull the log into its own storage before it ages out, the same as it would against any platform whose native window falls short of that requirement.
Paragon holds SOC 2 Type II; ISO 27001 is in progress. The fuller certification comparison across all seven platforms is in which integration platforms are SOC 2 compliant.
Where Paragon sits in the audit trail
Each downstream connection authenticates as a specific end user — the customer's own end user, not a shared service account — through per-user OAuth or API-key credentials. That identity carries through to every action an agent calls, whether it's called directly or exposed as a tool over MCP. When the action runs, Paragon logs the acting end user, the action, the object it touched, the outcome, and the timestamp.
Here are the fields a reviewer can expect an Event Log entry to carry, per Paragon's Event Logs documentation — field names only, not an example payload:
Failures are handled separately from the audit log. Workflow and credential failures route to Slack, Datadog, Sentry, or New Relic for real-time alerting — that's failure monitoring, kept apart from the per-action log described above, not a general audit feed.
Paragon's underlying security posture — SOC 2 Type II, per-tenant isolation, encryption at rest and in transit — is published at Paragon's trust portal. To see how the log looks against your own tenant and user model, request a demo.
FAQ
What counts as an "audit log" for AI data access, versus a workflow log? A workflow log confirms a job ran — started, finished, or failed. An audit log for AI data access has to answer a narrower question: which end user's record did the agent read or write, with which action, and when. Most platforms compared here produce the first kind by default. Paragon logs integration actions with end-user attribution (actor, action, object, outcome, timestamp), searchable in-product, which is the second kind.
Does an integration platform identify which end user an AI agent acted as? Not by default, for four of the seven platforms compared here — Workato, Boomi, MuleSoft, and Zapier's own docs identify only the platform's own workspace or admin user who configured or triggered an action; none of the four document a customer's downstream end user in that trail (checked Sept 2026). Celigo and Tray.ai narrowed that gap in 2026 for MCP tool calls only: Celigo surfaces the authenticated end user in its MCP request log once a connection is migrated to its end-user model, and Tray.ai's Agent Gateway records the executing end user under Dynamic Authentication — in both cases only for MCP tool calls, not the platform's wider audit trail. Paragon logs an endUserId with end-user attribution, identifying the specific end user an agent acted on behalf of, without a migration or configuration step.
Can audit logs be forwarded to a SIEM? Workato, Boomi, Tray.ai, MuleSoft (tier-gated to Anypoint Integration Advanced or Titanium), and Zapier (Enterprise) offer native streaming — Boomi's is OpenTelemetry-based (GA September 2025), also available via a third-party connector (Splunk app, Datadog integration). Celigo has no SIEM streaming, only CSV/API export. Paragon doesn't forward them at all — actions are logged (actor, action, object, outcome, timestamp) and searchable in-product.
How long are audit logs retained? It varies sharply by vendor and plan, so no single number represents the field. MuleSoft defaults to one year for new organizations, up to six years for legacy accounts; Celigo holds a minimum of one year; Zapier keeps six months (Team) or twelve (Enterprise); Tray.ai's workflow-execution logs run 7 to 30 days by plan; Boomi shows 30 days in-console with an indefinite underlying store; Workato's docs put it at one year (its marketing page still shows an older 90-day figure). Paragon holds Event Logs for 30 days on an Enterprise plan, or 7 days on Pro and below.
What should a security reviewer ask for when evaluating AI agent audit logs? Ask for three specifics: whether the log identifies the end user an agent acted as, not just the platform user who configured the connection; the actual retention window versus any marketing figure; and whether SIEM forwarding is native — as with Workato, Boomi, Tray.ai, MuleSoft, and Zapier — or absent entirely, as with Paragon. Paragon answers the first with per-action, end-user-attributed logs; the second with a published 30-day (Enterprise) or 7-day (Pro and below) window; the third with a plain no on native forwarding — the data is searchable in-product instead.









