AI data market
Can audit logs and activity histories be licensed for AI training?
By SourceX Editorial · Reviewed by Noah Loul ·
Short answer
Audit logs and activity histories can be licensed for AI training when three conditions hold: the events record your own operations or you have rights to the usage data, identifiers and personal details are removed, and the tools' vendor terms allow the use. Workflow histories tied to outcomes, such as issue and ticket histories, carry the most value.
Key takeaways
- Workflow histories that link each step to an outcome are worth far more than sign-in or system logs.
- Logs of employees using internal tools are usually the company's records; logs of customers using your product usually are not.
- Event streams identify people through IDs, IP addresses, devices and free text, so de-identification covers every field.
- Security audit logs are usually kept out because they map how a company's defenses work.
- Evaluation use and training use should be named separately in the license.
Can audit logs be licensed? Yes, if three conditions hold#
Audit logs and activity histories can be licensed for AI training when three conditions hold: the events describe your own operations or you have clear rights to the usage data, identifiers and personal details are removed, and the terms of the tools that produced the logs allow the use. Most companies find that some log families pass easily and others fail on the first condition.
Value depends on linkage. A stream of logins says little about how work gets done, while an issue history that shows each status change, comment and linked commit through to release shows a full decision path.
| Condition | Usually passes when | Usually fails when |
|---|---|---|
| Whose data | Events record employees using internal tools such as Jira, GitHub or Zendesk | Events record customers using your product, and contracts limit use to providing the service |
| Personal details | Actor IDs can be replaced with consistent pseudonyms and free text can be cleaned | IP addresses, locations or device IDs cannot be separated from the events |
| Vendor terms | Logs are exported through standard admin features for your own records | Terms restrict onward use of exported or API-derived data |
Which logs are worth licensing?#
The logs worth licensing are the ones that record people making decisions and the results that followed. Developers building AI agents look for step-by-step traces: the state at the start, each action taken and the outcome. An activity history supplies the shape of that trace, and the tickets, commits or records it points to supply the content.
Workflow histories usually carry the most value with the fewest problems, because they record your own staff doing their jobs and their outcomes are written into the record.
| Log family | Example sources | What it shows | Typical value |
|---|---|---|---|
| Workflow histories | Jira issue history, Zendesk ticket events, GitHub pull request timelines | Who changed what, in what order, through to the outcome | High: decision paths linked to results |
| CI/CD and deployment logs | Build, test and deploy pipelines, rollback records | How code moved from change to production and what failed | Moderate to high for coding agents, after secret removal |
| Record change histories | Field history in Salesforce or NetSuite, ERP change logs | Edits to orders, accounts and prices over time | Moderate: useful with the surrounding records |
| Product activity events | Event tables or analytics tools inside your SaaS product | Sequences of user actions in your product | Potentially high, but usually customer data |
| Security audit logs | Okta, Google Workspace or Microsoft 365 admin logs, cloud audit trails | Sign-ins, permission changes and admin actions | Low for training, high security exposure |
Whose data is in the log?#
Whose data sits in a log decides most licensing questions. When the actors are your own employees using internal tools, the company generally controls the records, subject to employee notices and any privacy laws that may apply. When the actors are customers using your product, the logs are usually customer data under your MSA and data processing terms.
Read how your customer contracts define customer data, usage data and aggregated or de-identified data. Some contracts let a vendor use de-identified usage data to improve its own services but say nothing about licensing it to others. Silence is not permission, so general counsel should review before product events go anywhere near a package. Shared projects need the same check: a Jira project where client staff or contractors also work holds actions by people who sit under someone else's agreement.
How do you remove identities from event streams?#
Removing identities from event streams takes more than deleting a name column, because logs identify people through many fields at once. Work through each field family in turn.
Tools help but do not finish the job. Presidio's documentation states that automated detection gives no guarantee of finding all sensitive information, and TruffleHog, an open-source secret scanner, covers logs as well as Git repositories and chats; both should be followed by human sampling.
- Replace user, agent and account IDs with consistent pseudonyms so sequences stay intact.
- Drop IP addresses, device identifiers and precise locations.
- Coarsen timestamps where exact times are not needed, while keeping the order of events.
- Run personal-detail detection over comments, descriptions and error messages, then sample by hand.
- Scan URLs, headers and pasted configuration for credentials, and confirm any live keys are revoked.
- Remove internal hostnames, network ranges and security settings that would map your infrastructure.
Why do security exposure and vendor terms matter?#
Security exposure is the reason most companies keep security audit logs out entirely. Sign-in patterns, permission changes and admin actions describe how your defenses work, and their training value rarely justifies the risk.
Vendor terms are the second check. Logs exported through a SaaS tool's standard admin features are generally your records, but platform terms increasingly restrict what apps may do with data pulled through APIs. Slack's API terms bar third-party apps from using API data to train a large language model, and HubSpot's updated developer terms restrict using API data to train or improve AI models, with a carve-out for single-customer use. Note the export route for each log family in the rights review so the question is answered once, not in every negotiation.
If a buyer specifically wants security operations data, for example to train agents that triage alerts, treat it as a separate project with its own security review, a narrower scope and heavier redaction, rather than folding it into a general package.
Illustrative: an elevator service software vendor separates its logs#
Illustrative: a fictional software vendor serving elevator service contractors reviews its logs after a developer asks about agent training data. The CTO lists Jira issue histories, GitHub pull request timelines and CI results, Zendesk ticket events, Okta logs and the product's own event table, which records how customers' dispatchers and elevator technicians use the app.
General counsel reads the MSA and finds that product events are customer data usable only to provide and improve the service, so they stay out, as do the Okta logs. The package covers Jira, GitHub, CI and Zendesk histories linked by issue keys, with staff pseudonymized, customer names replaced, comments run through detection and sampled, and secrets scanned.
Outcome: a package that shows how bugs moved from report to fix to release, with no customer usage data and no security logs.
How SourceX assesses log data#
Log data is rated against the SourceX Enterprise Data Value Framework like any other record family, and its drivers pull in different directions. Human-generated signal and AI utility raise the value of workflow histories, privacy burden and preparation cost lower the net value of product events, and rights often settle the question before value is discussed.
Log families are scoped one at a time in the Rights step of the SourceX five-step transaction, then prepared, approved and delivered, with the company approving each step. The SourceX Evidence Packet names the included log families, the identity-removal method and the approved uses, so a buyer's reviewers can check them without asking for raw logs.
Frequently asked questions
Are machine-written logs really human-generated data?
Partly. Events triggered by people, such as a status change, a review approval or a reassignment, reflect human decisions even though software writes the log line. System metrics, health checks and bot activity do not. Label automated events so a buyer can separate them, because mixing them in lowers the signal.
Is customer consent needed before licensing product usage logs?
The answer turns on your customer contracts, the privacy notices your customers' users saw and the laws that may apply to them. Many contracts limit use of customer data to providing the service, so licensing usually needs explicit permission or is excluded. Aggregated statistics raise different questions from event-level records, and counsel should review both.
How much history do audit logs usually keep?
Often less than people expect. Many tools keep detailed event history for a limited period that depends on plan and settings, while issue trackers and help desks often keep full change histories with each record. Check retention settings now, because history deleted by policy cannot be recovered for a license.
Can logs be licensed for evaluation rather than training?
Yes. Some developers use activity histories to test whether an agent follows realistic sequences, without training on them. Name evaluation as a separate permitted use in the license, with its own limits on copying and retention, so records are not quietly reused for training.
Should bot and integration events stay in the package?
Keep them if they are labeled, because automations are part of how real work happens and an agent may need to recognize them. Unlabeled bot events mixed with human actions make sequences misleading, so tag the actor type during preparation.
Sources
- Presidio's documentation warns that because it uses automated detection mechanisms, there is no guarantee it will find all sensitive information, and additional systems and protections should be employed. Source
- TruffleHog is an open-source secret scanner that scans sources including Git, chats, wikis, logs, object stores and filesystems. Source
- Slack's API Terms of Service state that a provider of an application offered for use outside its own organization may not use API Data to train a large language model, and may not bulk export Slack message and file data except where an additional agreement expressly allows it. Source
- HubSpot's updated Developer Terms restrict using data accessed through HubSpot APIs to train, fine-tune or improve AI or machine learning models, with a carve-out for legitimate single-customer use cases. Source
Related resources
See if your company qualifies
A short company assessment. No data uploads are needed.