Something new is happening in how teams run their AI agents: AI assistants connected over MCP can now propose changes, update glossaries, and run tests. That's a real capability, and it belongs in your security review, because a system that can be changed through three interfaces needs a change record that knows the difference.
Security teams always ask three questions of a system like this. What changed, and who changed it? Can you delete our customers' data? And what's connected to it? This series of capabilities is Ada's answer.
What changed, who changed it, and through what
Audit log captures tracked configuration changes to your AI agent: team access and SSO changes, edits to Knowledge, Actions, Playbooks, and Processes, API key activity, test and simulation runs, and more. Each entry carries the actor, the activity, the entity, the timestamp, and the interface the change came through - the dashboard, the public API, or an AI assistant connected via MCP. That last part matters most: as AI assistants become operators, interface attribution is how you keep the accountability trail intact. Coverage keeps growing: Glossary changes joined the log now as well.
The record is yours to consume three ways: pull it through the Platform API, built and load-tested for SIEM-style polling; push it by webhook into the monitoring tooling your team runs; or work with it in the dashboard with search, filters, and CSV export.
Deletion as a process with a receipt
When your team needs to remove end users' data, the work should be a tracked process, not a project. Bulk end-user deletion removes up to 1,000 end users in a single job through the API, with job tracking so your team has a record that the request was received, executed, and completed.
Every AI-assistant connection, attributed and revocable
As teams connect AI assistants to Ada through MCP, a new question arrives in the security review: who has connected what? The MCP connections page answers it. It lists every authorized AI-assistant connection to your agent, shows who granted it and when, and lets you revoke any connection immediately.
Why it matters
AI agents are becoming systems that other AI systems operate. The teams adopting them fastest aren't the ones that skip the security review - they're the ones whose vendors can actually answer it. Change records with interface-level attribution, deletion with a receipt, and connection visibility with revocation are the start of that answer, and the review is exactly where they belong.
Three questions, three good answers. That's what control you can trust looks like.