The distinction between logging access and being able to reconstruct why the agent acted is the whole thing, and most trace setups capture the former while missing the decision inputs that actually explain a choice. What holds up to a regulator is the prompt, retrieved context, and tool outputs at each step, versioned so you can replay it. Are you storing enough of the run to reconstruct a decision, or just enough to see that it happened?