Skip to main content

Swif Agentic Security Logging Policy

Overview

The Swif Agentic Security Logging Policy enables or disables audit logging for supported AI-agent activity on managed devices.

When logging is enabled, the Swif Agentic Security agent can report supported agent actions to Swif so administrators can review activity, investigate risky behavior, and maintain an audit record. Reported activity can be viewed from the device's Agentic Security area in Swif.

The policy supports:

  • macOS

  • Windows

  • Linux

  • Company-owned devices

  • BYOD devices

Important: This policy controls logging. It does not install the Swif Agentic Security agent. Install the agent on the target devices before assigning the logging policy.

What the Policy Does

The policy contains one configurable setting: Enabled.

When enabled, the policy turns on Agentic Security audit logging on assigned devices. Depending on the supported AI agent and integration, administrators can use the resulting activity records to:

  • Review AI-agent actions across managed devices

  • See supported activity as it is reported

  • Filter events by time, subsystem, and risk level

  • Review actions classified as Safe, Risky, or Danger

  • Investigate unexpected or potentially destructive behavior

  • Maintain evidence for security and compliance reviews

Swif's Agentic Security documentation also describes automatic redaction of detected API keys, passwords, and credentials before they appear in logs. Redaction reduces exposure, but administrators should still treat activity records as potentially sensitive security data.

Requirements

Requirement

Details

Swif access

An active Swif workspace and an administrator with permission to create and assign policies

Supported platforms

macOS, Windows, and Linux

Device ownership

Company-owned and BYOD devices

Device enrollment

The device must be enrolled in Swif when the policy is delivered through Swif device management

Agentic Security

The Swif Agentic Security agent must be installed and active on the target device

Connectivity

The device must be online to receive the policy and report new activity to Swif

AI-agent support

Activity must come from an AI agent or integration supported by the installed Agentic Security version

For Agentic Security installation and supported platforms, see Getting Started with Swif's Agentic Security for Enterprise.

Recommended Configuration

For organization-managed devices that use supported AI agents, set:

Setting

Recommended value

Enabled

Enabled

Start with a small pilot group. Generate controlled AI-agent activity, confirm that expected events appear, and review the information visible to administrators before expanding the assignment.

For BYOD deployments, document the monitoring purpose, scope, and retention practices for device users. Confirm that your organization has provided any notice or obtained any authorization required by applicable law and internal policy.


Policy Settings

Enabled

Controls whether Swif Agentic Security logging is active.

Value

Behavior

Enabled

Enables Agentic Security audit logging on assigned devices. Supported AI-agent activity can be reported to Swif for monitoring and review.

Disabled

Explicitly disables Agentic Security logging on assigned devices. New supported activity is no longer reported through this logging configuration after the device receives the change.

Unset

Does not explicitly instruct the Agentic Security agent to enable or disable logging. The device's existing or separately managed state can remain in effect.

The setting is optional and has no preset policy default. If your goal is to collect Agentic Security activity, explicitly select Enabled instead of leaving the field unset.

This policy does not provide settings for:

  • Selecting individual event categories

  • Changing risk-classification logic

  • Configuring log-retention periods

  • Allowing or denying particular tools

  • Installing or removing the Agentic Security agent

  • Configuring OpenClaw tools or runtime behavior

Use the applicable Agentic Security or OpenClaw policies for controls that are outside this logging policy.

Create the Policy

  1. Sign in to the Swif Admin Console.

  2. Go to Agentic Security > Policy.

  3. Select Create new policy.

  4. Start from scratch and select Swif Agentic Security Logging Policy.

  5. Enter a descriptive policy name, such as:

    Enable Agentic Security Logging
  6. Add a description explaining the purpose and intended device scope.

  7. Set Enabled to Enabled.

  8. Assign the policy to selected test devices or a pilot device group.

  9. Review the configuration and finish creating the policy.

  10. Allow the assigned devices to check in.

Assigning policies to device groups is recommended when new devices should automatically inherit the same logging configuration. For the general assignment workflow, see Assigning policies to devices or groups.

Verify the Policy

After deployment:

  1. Confirm that the target device is online in Swif.

  2. Open the policy and review its deployment report.

  3. Confirm that the policy reports as installed or successfully applied to the test device.

  4. Open the device in Swif.

  5. Go to the device's Agentic Security or activity view.

  6. Generate a controlled action using a supported AI agent on the device.

  7. Confirm that a corresponding event appears in Swif.

  8. Review the event's timestamp, subsystem, action details, and risk classification when available.

Use a harmless test action, such as reading a temporary test file. Do not test logging by deleting production data, changing security controls, or exposing credentials.

Note: A successful policy status confirms that Swif delivered the configuration. It does not by itself confirm that the Agentic Security agent is running or that a supported AI agent has generated an event. Verify both policy status and actual test activity.

Privacy and Security Considerations

Agentic Security logs may reveal information about developer activity, commands, files, tools, repositories, and security-relevant events. Treat these records as sensitive organizational data.

Before broad deployment:

  • Define the security and compliance purpose for collecting AI-agent activity.

  • Tell users what activity is monitored, especially on BYOD devices.

  • Limit access to authorized IT, security, compliance, and incident-response personnel.

  • Review retention requirements and avoid retaining records longer than necessary.

  • Do not rely on redaction as the only control protecting secrets.

  • Avoid entering production credentials or sensitive personal information into AI-agent prompts.

  • Review applicable employment, privacy, and monitoring requirements in the locations where devices and users operate.

Logging provides visibility and audit evidence. It does not automatically block a risky action or reverse a change performed by an AI agent.

Interaction With Other Agentic Security Policies

The logging policy provides the activity record used for monitoring and investigation. Other Agentic Security policies may manage different parts of an agent's configuration or permissions.

For example, the Swif OpenClaw Config Tools Policy can manage supported OpenClaw configuration and tool-use controls. Assigning an OpenClaw policy does not replace the need to enable logging when administrators require an audit trail.

Avoid assigning conflicting Agentic Security logging policies to the same device. If one policy enables logging and another disables it, the resulting state can depend on which configuration is applied most recently.


Troubleshooting

The Policy Is Assigned but No Events Appear

Check the following:

  • Enabled is explicitly set to Enabled, not Unset.

  • The policy reports as successfully applied.

  • The device is online.

  • The Swif Agentic Security agent is installed and active.

  • The installed agent version supports the AI tool being tested.

  • The test action was generated after logging was enabled.

  • The selected time range and filters include the test event.

  • A firewall, proxy, VPN, or security product is not blocking the Agentic Security connection.

Generate a new, harmless test action after confirming these items.

The Device Shows a Missing Policy State

The Agentic Security activity view can identify devices that do not have a logging policy assigned. Select the available Create/Assign action for the logging policy, or create the policy through Policy Management and assign it to the affected device or group.

Confirm that the assigned policy has Enabled explicitly selected.

The Agentic Security Agent Is Missing

The logging policy does not install the Agentic Security agent.

Use Swif's Agentic Security setup workflow to deploy the appropriate platform-specific agent:

  • Apple Agentic Security Policy for supported macOS devices

  • Windows Agentic Security Policy for supported Windows devices

  • Linux Agentic Security Policy for supported Linux devices

After installation, return to the logging policy and verify the assignment.

The Device Is Offline

An offline device cannot receive a new policy or report new activity to Swif in real time. Restore network access, allow the device and Agentic Security agent to reconnect, and then generate a new test event.

Do not assume that every action performed while the device was offline will appear later. Verify the behavior using the installed agent version and your deployment configuration.

Events Appear on One Device but Not Another

Compare:

  • Operating system and version

  • Agentic Security agent version and status

  • Policy assignment and deployment status

  • Device ownership or enrollment mode

  • AI agent and integration being used

  • Network, proxy, VPN, and endpoint-security configuration

  • Activity filters and selected time range

Test each device with the same supported AI-agent action to isolate the difference.

Sensitive Information Appears in an Event

Swif is designed to detect and redact supported secrets, but no automated redaction system should be treated as complete.

If sensitive information appears:

  1. Restrict access to the affected record.

  2. Rotate any exposed credential or token immediately.

  3. Determine which prompt, command, file, or tool exposed the value.

  4. Review administrator access and retention requirements.

  5. Contact Swif Support with a sanitized example that does not reproduce the secret.

Disable Logging

To explicitly stop Agentic Security logging on assigned devices:

  1. Open the Swif Agentic Security Logging Policy.

  2. Set Enabled to Disabled.

  3. Save and redeploy the policy.

  4. Allow the device to check in.

  5. Confirm that the updated policy was applied.

  6. Generate a controlled test action and confirm that no new event is reported through this logging configuration.

Disabling logging does not automatically uninstall the Agentic Security agent or delete activity that was collected previously. Use the separate Agentic Security removal workflow if the agent must also be removed.

Removing the policy assignment is not the same as explicitly disabling logging. If logging must be turned off, deploy Disabled first and verify the change before removing the assignment.

Summary

The Swif Agentic Security Logging Policy provides a single organization-managed control for enabling or disabling AI-agent audit logging on macOS, Windows, and Linux devices.

For a reliable deployment:

  1. Install and verify the Swif Agentic Security agent.

  2. Create the logging policy and explicitly set Enabled to Enabled.

  3. Assign it to a pilot device or device group.

  4. Generate harmless test activity and confirm that events appear.

  5. Review privacy, access, and retention requirements before broad deployment.

  6. Use separate policies when you need tool restrictions or agent-specific configuration controls.

Related Resources

Did this answer your question?