Overview
The Swif Agentic Security Logging Policy enables or disables audit logging for supported AI-agent activity on managed devices.
When logging is enabled, the Swif Agentic Security agent can report supported agent actions to Swif so administrators can review activity, investigate risky behavior, and maintain an audit record. Reported activity can be viewed from the device's Agentic Security area in Swif.
The policy supports:
macOS
Windows
Linux
Company-owned devices
BYOD devices
Important: This policy controls logging. It does not install the Swif Agentic Security agent. Install the agent on the target devices before assigning the logging policy.
What the Policy Does
The policy contains one configurable setting: Enabled.
When enabled, the policy turns on Agentic Security audit logging on assigned devices. Depending on the supported AI agent and integration, administrators can use the resulting activity records to:
Review AI-agent actions across managed devices
See supported activity as it is reported
Filter events by time, subsystem, and risk level
Review actions classified as Safe, Risky, or Danger
Investigate unexpected or potentially destructive behavior
Maintain evidence for security and compliance reviews
Swif's Agentic Security documentation also describes automatic redaction of detected API keys, passwords, and credentials before they appear in logs. Redaction reduces exposure, but administrators should still treat activity records as potentially sensitive security data.
Requirements
Requirement | Details |
Swif access | An active Swif workspace and an administrator with permission to create and assign policies |
Supported platforms | macOS, Windows, and Linux |
Device ownership | Company-owned and BYOD devices |
Device enrollment | The device must be enrolled in Swif when the policy is delivered through Swif device management |
Agentic Security | The Swif Agentic Security agent must be installed and active on the target device |
Connectivity | The device must be online to receive the policy and report new activity to Swif |
AI-agent support | Activity must come from an AI agent or integration supported by the installed Agentic Security version |
For Agentic Security installation and supported platforms, see Getting Started with Swif's Agentic Security for Enterprise.
Recommended Configuration
For organization-managed devices that use supported AI agents, set:
Setting | Recommended value |
Enabled | Enabled |
Start with a small pilot group. Generate controlled AI-agent activity, confirm that expected events appear, and review the information visible to administrators before expanding the assignment.
For BYOD deployments, document the monitoring purpose, scope, and retention practices for device users. Confirm that your organization has provided any notice or obtained any authorization required by applicable law and internal policy.
Policy Settings
Enabled
Controls whether Swif Agentic Security logging is active.
Value | Behavior |
Enabled | Enables Agentic Security audit logging on assigned devices. Supported AI-agent activity can be reported to Swif for monitoring and review. |
Disabled | Explicitly disables Agentic Security logging on assigned devices. New supported activity is no longer reported through this logging configuration after the device receives the change. |
Unset | Does not explicitly instruct the Agentic Security agent to enable or disable logging. The device's existing or separately managed state can remain in effect. |
The setting is optional and has no preset policy default. If your goal is to collect Agentic Security activity, explicitly select Enabled instead of leaving the field unset.
This policy does not provide settings for:
Selecting individual event categories
Changing risk-classification logic
Configuring log-retention periods
Allowing or denying particular tools
Installing or removing the Agentic Security agent
Configuring OpenClaw tools or runtime behavior
Use the applicable Agentic Security or OpenClaw policies for controls that are outside this logging policy.
Create the Policy
Sign in to the Swif Admin Console.
Go to Agentic Security > Policy.
Select Create new policy.
Start from scratch and select Swif Agentic Security Logging Policy.
Enter a descriptive policy name, such as:
Enable Agentic Security Logging
Add a description explaining the purpose and intended device scope.
Set Enabled to Enabled.
Assign the policy to selected test devices or a pilot device group.
Review the configuration and finish creating the policy.
Allow the assigned devices to check in.
Assigning policies to device groups is recommended when new devices should automatically inherit the same logging configuration. For the general assignment workflow, see Assigning policies to devices or groups.
Verify the Policy
After deployment:
Confirm that the target device is online in Swif.
Open the policy and review its deployment report.
Confirm that the policy reports as installed or successfully applied to the test device.
Open the device in Swif.
Go to the device's Agentic Security or activity view.
Generate a controlled action using a supported AI agent on the device.
Confirm that a corresponding event appears in Swif.
Review the event's timestamp, subsystem, action details, and risk classification when available.
Use a harmless test action, such as reading a temporary test file. Do not test logging by deleting production data, changing security controls, or exposing credentials.
Note: A successful policy status confirms that Swif delivered the configuration. It does not by itself confirm that the Agentic Security agent is running or that a supported AI agent has generated an event. Verify both policy status and actual test activity.
Privacy and Security Considerations
Agentic Security logs may reveal information about developer activity, commands, files, tools, repositories, and security-relevant events. Treat these records as sensitive organizational data.
Before broad deployment:
Define the security and compliance purpose for collecting AI-agent activity.
Tell users what activity is monitored, especially on BYOD devices.
Limit access to authorized IT, security, compliance, and incident-response personnel.
Review retention requirements and avoid retaining records longer than necessary.
Do not rely on redaction as the only control protecting secrets.
Avoid entering production credentials or sensitive personal information into AI-agent prompts.
Review applicable employment, privacy, and monitoring requirements in the locations where devices and users operate.
Logging provides visibility and audit evidence. It does not automatically block a risky action or reverse a change performed by an AI agent.
Interaction With Other Agentic Security Policies
The logging policy provides the activity record used for monitoring and investigation. Other Agentic Security policies may manage different parts of an agent's configuration or permissions.
For example, the Swif OpenClaw Config Tools Policy can manage supported OpenClaw configuration and tool-use controls. Assigning an OpenClaw policy does not replace the need to enable logging when administrators require an audit trail.
Avoid assigning conflicting Agentic Security logging policies to the same device. If one policy enables logging and another disables it, the resulting state can depend on which configuration is applied most recently.
Troubleshooting
The Policy Is Assigned but No Events Appear
Check the following:
Enabled is explicitly set to Enabled, not Unset.
The policy reports as successfully applied.
The device is online.
The Swif Agentic Security agent is installed and active.
The installed agent version supports the AI tool being tested.
The test action was generated after logging was enabled.
The selected time range and filters include the test event.
A firewall, proxy, VPN, or security product is not blocking the Agentic Security connection.
Generate a new, harmless test action after confirming these items.
The Device Shows a Missing Policy State
The Agentic Security activity view can identify devices that do not have a logging policy assigned. Select the available Create/Assign action for the logging policy, or create the policy through Policy Management and assign it to the affected device or group.
Confirm that the assigned policy has Enabled explicitly selected.
The Agentic Security Agent Is Missing
The logging policy does not install the Agentic Security agent.
Use Swif's Agentic Security setup workflow to deploy the appropriate platform-specific agent:
Apple Agentic Security Policy for supported macOS devices
Windows Agentic Security Policy for supported Windows devices
Linux Agentic Security Policy for supported Linux devices
After installation, return to the logging policy and verify the assignment.
The Device Is Offline
An offline device cannot receive a new policy or report new activity to Swif in real time. Restore network access, allow the device and Agentic Security agent to reconnect, and then generate a new test event.
Do not assume that every action performed while the device was offline will appear later. Verify the behavior using the installed agent version and your deployment configuration.
Events Appear on One Device but Not Another
Compare:
Operating system and version
Agentic Security agent version and status
Policy assignment and deployment status
Device ownership or enrollment mode
AI agent and integration being used
Network, proxy, VPN, and endpoint-security configuration
Activity filters and selected time range
Test each device with the same supported AI-agent action to isolate the difference.
Sensitive Information Appears in an Event
Swif is designed to detect and redact supported secrets, but no automated redaction system should be treated as complete.
If sensitive information appears:
Restrict access to the affected record.
Rotate any exposed credential or token immediately.
Determine which prompt, command, file, or tool exposed the value.
Review administrator access and retention requirements.
Contact Swif Support with a sanitized example that does not reproduce the secret.
Disable Logging
To explicitly stop Agentic Security logging on assigned devices:
Open the Swif Agentic Security Logging Policy.
Set Enabled to Disabled.
Save and redeploy the policy.
Allow the device to check in.
Confirm that the updated policy was applied.
Generate a controlled test action and confirm that no new event is reported through this logging configuration.
Disabling logging does not automatically uninstall the Agentic Security agent or delete activity that was collected previously. Use the separate Agentic Security removal workflow if the agent must also be removed.
Removing the policy assignment is not the same as explicitly disabling logging. If logging must be turned off, deploy Disabled first and verify the change before removing the assignment.
Summary
The Swif Agentic Security Logging Policy provides a single organization-managed control for enabling or disabling AI-agent audit logging on macOS, Windows, and Linux devices.
For a reliable deployment:
Install and verify the Swif Agentic Security agent.
Create the logging policy and explicitly set Enabled to Enabled.
Assign it to a pilot device or device group.
Generate harmless test activity and confirm that events appear.
Review privacy, access, and retention requirements before broad deployment.
Use separate policies when you need tool restrictions or agent-specific configuration controls.