Why a normal log is not evidence
A standard application log is a mutable file. Whoever holds write access can append, edit, or delete a line, and there is no way for a reader to tell after the fact. A cloud logging dashboard is the same problem with extra steps: the provider, an admin, or a compromised process can rewrite history, and the log's own timestamps offer no defence because they were written by the same trusted party.
For AI agents this gap matters more than for ordinary software. An agent takes actions on your behalf: it calls tools, moves data, spends budget, and touches other systems. When something goes wrong, "the log says the agent did X" only helps if the log could not have been quietly changed to say something else. A record you have to trust is not evidence. It is a claim.
The fix is not a better dashboard. It is changing the record so that tampering is detectable by anyone, without access to your infrastructure.