Skip to content

Traces Open-Core

Traces are the audit trail of every AI agent request that flows through the Intutic proxy. Each trace records what happened, what enforcement action was applied, and how much it cost.

In open-core the proxy writes traces locally as daily-sharded JSONL under ~/.intutic/logs/ (traces-YYYY-MM-DD.jsonl, one record per line, capped at 64MB/day — see Local vs connected below for what that cap means for you). With no connected control plane, intutic traces list / intutic traces inspect now read that log directly — no cat/jq needed, though you're always free to do that too. The REST API shown alongside each CLI example below is the connected-mode equivalent, and connected mode is still the only way to see a trace's compliance score and enforcement action.

What's in a trace?

Each execution trace contains (field names as written to the local JSONL; connected mode camelCases them over the API):

FieldDescription
trace_idUnique identifier (tr_ prefix)
session_idThe agent session this trace belongs to
created_atISO 8601 timestamp of the request
model / providerThe LLM model and provider used
requested_model / actual_model_routedThe model the caller asked for vs. the one that actually served the request
raw_input_tokens / output_tokensToken counts
raw_cost_usd / actual_cost_usdCost had the requested model served it, vs. the actual cost of the routed model's response
cache_hit / cache_read_input_tokens / cache_creation_input_tokensProvider prompt-cache accounting
latency_msRequest latency
verdictThe proxy's own enforcement verdict — locally, exactly one of allowed, killed, upstream_error, reasked, hijacked
harness_typeWhich coding agent/IDE issued the request

Two fields you may see referenced elsewhere are connected-mode only, with no local equivalent: a compliance/quality score, and the four-way BYPASS/ENHANCE/HIJACK/KILL enforcement-action vocabulary used by the control plane's PCAS layer. A standalone proxy's own verdict field uses a different, narrower vocabulary (above) — allowed ≠ BYPASS, and there is no local equivalent of ENHANCE or HIJACK's control-plane meaning.

Local vs connected

Local (no control plane)Connected
Data source~/.intutic/logs/traces-*.jsonl, read directlyControl-plane API
traces list / inspectRead the local logQuery the API
Compliance / quality scoreNot available — never fabricated as a placeholderAvailable
Enforcement actionverdict only (allowed/killed/upstream_error/reasked/hijacked)BYPASS/ENHANCE/HIJACK/KILL
Filtering--verdict--action
History depthWhatever's on disk, capped at 64MB/day per shard — see belowRetained per your plan
--json output shape{traces, total, malformedLines, cappedFiles} — its own local shapeTraceListResult

The 64MB/day cap is real, and the local reader is the only place you can learn you've hit it. Past that size, the proxy silently drops further writes for the rest of that day rather than growing the file without bound — so a very high-traffic day's trace count from intutic traces list may be a floor, not a complete record. The CLI warns you explicitly when a day-file it read had already reached the cap.

Listing traces

CLI

bash
# List last 20 traces (default)
intutic traces list

# Show 50 traces from the last 7 days
intutic traces list --limit 50 --since 7d

# Filter by enforcement action (connected mode only)
intutic traces list --action KILL

# Filter by verdict (local mode only)
intutic traces list --verdict killed

# Filter by model
intutic traces list --model claude-4-sonnet

# Output as JSON
intutic traces list --json

With no connected control plane, list reads ~/.intutic/logs/ directly — no compliance-score column (there is no local compliance score) and --action refuses to run, since BYPASS/ENHANCE/HIJACK/KILL don't exist locally; use --verdict instead. See Local vs connected.

CLI options:

OptionDescriptionDefault
--limit <n>Number of traces (1–100)20
--since <duration>Time window: 30m, 24h, 7d24h
--action <type>Filter: BYPASS, ENHANCE, HIJACK, KILL — connected mode only(all)
--verdict <type>Filter: allowed, killed, upstream_error, reasked, hijacked — local mode only(all)
--model <name>Filter by model name(all)
--jsonJSON output instead of tablefalse
--devUse local control planefalse

Inspecting a trace

CLI

bash
intutic traces inspect tr_abc123

With no connected control plane, inspect searches ~/.intutic/logs/ for a matching trace_id and prints the raw local record — token counts, costs, verdict, and everything else the proxy logged for that request, but no compliance score or corrective prompt card (both connected-mode-only). Connected mode's response additionally includes:

  • Compliance scores
  • Anomaly data (if any)
  • Corrective prompt card (if enforcement was applied)

Understanding enforcement actions

BYPASS

The request was fully compliant with all active SOPs. No modification needed. This is the ideal state.

ENHANCE

The request was compliant but could be improved. The proxy enriched the prompt, upgraded the model, or added context. The original intent is preserved.

HIJACK

The request was rerouted — typically for cost optimization (downgrading an expensive model to an equivalent cheaper one) or capability routing (sending a coding task to a code-specialized model).

KILL

The request was blocked. Common reasons:

  • Budget exceeded for the user's tier
  • SOP policy violation detected
  • A deterministic anomaly detector fired (loop, forbidden tool, credential sweep, budget breach)
  • Unauthorized tool call attempted

The circuit breaker for AI agents