What OAK records

Actions

Actions record every tool call an agent made, in order, with its result.

An action is one tool call the agent made. Where edits are the changes the hook captured on disk, actions are the complete picture of what the agent did β€” reads, searches, shell commands, web fetches, spawns β€” reconstructed from the transcript.

What counts as an action

An action is one tool call parsed from the transcript β€” a read, a search, a shell command, a web fetch, a subagent spawn, or a plan update β€” correlated with its result. Edits are the actions the hook also captured on disk; every other action is reconstructed from the transcript alone.

Seeing them

The Actions view presents them as a typed timeline, grouped by kind, with low-signal categories collapsed and errors always surfaced. It opens with any live conflicts and closes with the two audits β€” risk and egress β€” because those are read off the same stream of actions.

πŸ’‘
Actions are how the audits know

A destructive shell command, a read of a credential file, a fetch to a remote host β€” each is an action, and each is what Risk and Egress report on. The audits assert what ran, drawn from actions, never what was permitted.