Audit Log Investigation with Codex: API Runtime Pattern
A production playbook for audit log investigation in cross-industry operations using Codex: api runtime pattern, run-scoped inputs, logs, typed results, and artifacts.
Audience: Security operations teams
The problem
Security operations teams need audit log investigation to run repeatedly against audit logs, entity metadata, and escalation policy. In cross-industry operations, the pain is not one good answer; it is repeatability, auditability, exception handling, and evidence that survives handoff.
Implementation path
Package the audit log investigation instructions as a skill, send audit logs, entity metadata, and escalation policy as run-scoped inputs, execute with Codex, poll terminal status, and consume argo.result.v1 instead of parsing a transcript.
Tradeoffs and failure modes
The API boundary forces the workflow to define inputs, terminal states, and result shape before customers depend on it. For audit log investigation, the practical test is whether a second run can be debugged, retried, and consumed by a product without reading the raw agent transcript.
Run request
POST /api/skills/<skill_id>/run
provider=codex
workflow=audit-log-investigation
inputs[]=@./input-pack.zip
result_schema=argo.result.v1
Run this on Argo