Scout Trails Docs

Tool calls

A tool call is one invocation of a tool by an agent: reading or editing a file, running a shell command, fetching a URL, calling an MCP server. The Tool calls tab lists every call in the window, and each call has a detail page with its arguments, result and risk flags.

Status

Every tool call has one of three statuses:

StatusMeaning
okThe tool ran and succeeded.
errorThe tool ran and failed.
deniedThe tool never ran: a permission rule, a hook or a person refused it. A denied call has no duration and no result, and doesn’t count as an error anywhere in the dashboard.

Claude Code reports denials. Codex CLI reports only calls that ran, so its calls are always ok or error.

Type and category

Type is how the agent classifies the tool, for example builtin for the agent’s own tools and mcp for tools served by an MCP server.

Category is the Scout Trails grouping of the tool by what it does:

CategoryTools
file_readRead, Grep, Glob
file_writeWrite, Edit, NotebookEdit
code_execBash, Agent
web_fetchWebSearch, WebFetch
mcpany tool of type mcp
othereverything else

Tool calls list

Open Tool calls in the header. The subtitle reads “Every tool invocation in this window — filter by name, type, category, or outcome.”

Filters

FilterNarrows to
WindowThe time range. See Window.
ScopeThe whole organization, one team or one actor. See Scope.
Tool nameOne tool, or Any.
Tool typeOne type, or Any.
CategoryOne category, or Any.
Statusok, error, denied or Any.

The Tool name, Tool type and Category dropdowns list only values that occur in the selected window and scope. Change the window or scope and select Apply to refresh them. Filters combine: setting Tool name to Bash and Status to error shows failed shell commands. Reset clears every filter.

Columns

ColumnMeaning
ToolThe tool’s name. Select it to open the call.
TypeThe tool’s type.
CategoryThe tool’s category.
SessionThe session label (agent name and shortened session ID). Select it to open the session.
DurationHow long the call took, such as 850ms, 1.2s, 3m05s or 1h02m. — for a denied call.
Statusok, error or denied.
RiskThe most severe risk flag on the call: high, medium or low. — when the call has no flags.
WhenWhen the call happened, in UTC.

Calls are sorted newest first, 25 per page. Use Prev and Next to page; the label between them shows the page number and adds (last) on the final page.

When nothing matches, the table shows No tool calls match these filters. with Try 30 days and Clear filters buttons.

Tool call detail

Select a tool name in any list to open the call’s page. The heading is the tool name. ← All tool calls returns to the list, and the session label next to it opens the call’s session. A tool call ID that doesn’t exist in your organization returns a “404 page not found” page.

Overview card

The card header shows the call’s status. Fields that the agent didn’t report are left out or show —.

FieldMeaning
ToolThe tool’s name, followed by its type.
CategoryThe tool’s category.
AgentThe agent’s name and version.
ModelThe model that requested the call, when the agent reports it.
StartedWhen the call happened, in UTC.
DurationHow long the call took. — for a denied call.
ErrorThe error message. Shown only for a failed call that reported one.
DecisionThe permission decision recorded for the call, such as reject. Shown only when the agent reported one.
PromptThe ID of the user prompt that led to the call. Shown only when reported.
TraceThe OpenTelemetry trace ID. Shown only when reported.

Risk flags

Lists every flag raised on this call, most severe first, with Severity, Flag and Evidence. The flags and what triggers them are described in Risk flags. With none, the card shows No risk flags on this call.

Arguments and Result

The Arguments card shows the input the agent passed to the tool, and the Result card shows what the tool returned. The card header shows the full size in bytes. JSON is indented for reading.

Each card shows the first 8 KB. When the content is longer, select Show full arguments or Show full result to load the rest in place.

What appears here depends on what the agent sends:

  • Claude Code sends tool arguments only when OTEL_LOG_TOOL_DETAILS=1 is set. See Claude Code.
  • A denied call has no result.

When the agent sent nothing, the cards show No arguments recorded. or No result recorded.