Start here. This is the direct spoken answer to practice first.
Overview
A useful AI audit trail explains what happened without becoming a second ungoverned copy of every prompt and response.
I record the run identity, authenticated actor, tenant, model and prompt versions, policy decisions, tool calls, validated arguments, approvals, outcome, and side-effect receipts. Sensitive prompt and response bodies are omitted, redacted, tokenized, or stored separately with stricter access when the investigation need justifies them. Audit events are append-oriented, time-correlated, and protected from ordinary product editing.