Uploaded August 2026 | Updated September 2026, 11 hours ago
Every coding agent on your team's laptops — Claude Code, Codex, OpenClaw, pi — can read, write, and delete files with zero record of what happened. In this video, we walk through workos-audit-harness, an open-source tool that gives you a single, queryable audit log across every agent your engineers run, without ever putting a WorkOS API key on a laptop.
We cover:
• Why a lost sk_ key on a laptop means full environment compromise, and how device certificates + mTLS solve it
• How events get attributed to a real person via your MDM, not just a device ID
• What the audit log can prove (and the honest limits of what it can't)
• How to catch someone quietly turning off event reporting using token billing as a cross-check
• A live demo: asking the console who deleted a file, and getting a cited, timestamped answer
The project is MIT-licensed and includes integrations for Claude Code, Codex, OpenClaw, and pi, plus the proxy and chat console. Try it out and let us know what you think.
🔗 GitHub: github.com/workos/workos-audit-harness
🔗 Full post: workos.com/blog/audit-trail-for-every-coding-agent
Every coding agent on your team's laptops — Claude Code, Codex, OpenClaw, pi — can read, write, and delete files with zero record of what happened. In this video, we walk through workos-audit-harness, an open-source tool that gives you a single, queryable audit log across every agent your engineers run, without ever putting a WorkOS API key on a laptop.
We cover:
• Why a lost sk_ key on a laptop means full environment compromise, and how device certificates + mTLS solve it
• How events get attributed to a real person via your MDM, not just a device ID
• What the audit log can prove (and the honest limits of what it can't)
• How to catch someone quietly turning off event reporting using token billing as a cross-check
• A live demo: asking the console who deleted a file, and getting a cited, timestamped answer
The project is MIT-licensed and includes integrations for Claude Code, Codex, OpenClaw, and pi, plus the proxy and chat console. Try it out and let us know what you think.
🔗 GitHub: github.com/workos/workos-audit-harness
🔗 Full post: workos.com/blog/audit-trail-for-every-coding-agent










