The record-the-policy-decision bullet is easy to overlook, but it is what makes an incident reconstructable. I would log the policy version, authenticated subject, proposed tool plus normalized arguments, provenance IDs for retrieved inputs, and the explicit allow or deny reason. Without that decision trace, a prompt-injection or authorization failure can look identical in the final application logs.