AI Agent Tracer · Log Keeper · for IT

Log Keeper: install, deploy and operate

A technical guide for IT managers to the CodeDelta AI Agent Tracer Log Keeper: why coding-agent logs disappear, what the keeper copies and where, and how to install it on one machine or many.

1. Why it is needed: the logs vanish

AI coding agents (Claude Code, OpenAI Codex, Cursor, GitHub Copilot CLI, Gemini CLI, Google Antigravity) write a session log on the developer's machine. The log records what the agent was asked, every command it ran, the files it touched and the hosts it contacted. It is the only record of what the agent did on that machine.

The agents own those logs and remove them on their own schedule:

A review, an audit or an incident investigation that starts more than a month after the event will usually find the agent's record gone. The Log Keeper copies each machine's agent logs, on a schedule, into a keep folder before the agents remove them. The AI Agent Tracer reads a keep folder exactly as it reads the live logs.

For Claude Code only, retention can also be extended at the source through managed settings: "cleanupPeriodDays": 3650 (the value 0 fails validation). This lengthens Claude Code's own retention; it does not protect the logs from deletion by the user or cover the other agents.

2. What the keeper copies

AgentSource on the machine
Claude Code~/.claude/projects (session transcripts and sub-agent transcripts)
OpenAI Codex~/.codex/sessions
Cursor~/.cursor/projects, plus Cursor's state database state.vscdb (macOS: ~/Library/Application Support/Cursor/User/globalStorage/; Linux: ~/.config/Cursor/User/globalStorage/; Windows: %APPDATA%\Cursor\User\globalStorage\), which holds each session's name and model
GitHub Copilot CLI~/.copilot/session-state
Gemini CLI~/.gemini/tmp
Google Antigravity~/.gemini/antigravity/conversations

Only folders that exist are read. The keeper reads the sources and never modifies or deletes them.

3. How it copies

4. Safeguards

5. Choosing the keep folder: protected folders cannot be used

The scheduled job runs in the background without a window. Operating-system file protection blocks it in certain folders: on macOS a background job was refused files the app itself had written in Desktop and iCloud Drive, with Full Disk Access granted. The keeper therefore refuses these folders in the app (Save, Keep now, Keep automatically), on the command line and in the scheduled job, and nothing is saved, created, copied or scheduled there:

PlatformRefused as keep folder (and anything inside them)
macOSDesktop, Documents, Downloads, iCloud Drive (~/Library/Mobile Documents), cloud storage (~/Library/CloudStorage — OneDrive, Google Drive, Dropbox, Box; also ~/Dropbox, ~/Google Drive)
WindowsDesktop, Documents, Downloads, Pictures, Music, Videos, Favorites, OneDrive (including the folders named by %OneDrive%, %OneDriveCommercial%, %OneDriveConsumer%), Dropbox, Google Drive, iCloudDrive. Microsoft Defender's Controlled folder access guards Documents, Pictures, Music, Videos and Favorites, and OneDrive-redirected folders, when it is switched on.
LinuxNone refused.

Use a folder directly in the user's home folder, for example ~/tracer logs. On macOS, a background job wrote to such a folder without any permission grant. Include that folder in the machine's normal backup so a copy also exists off the machine.

6. Requirements

7. Install on one machine (the app)

  1. Open CodeDelta and choose AI Agent Tracer mode. The Log keeper line is under the folder field.
  2. Enter or select the keep folder (not a protected folder) and choose Keep images (full copy, compressed) or Maximise compaction. Press Save.
  3. Press Keep now for a first copy. A first copy of several hundred MB of logs takes a minute or two; Stop ends it and what is already kept stays.
  4. Choose when to keep automatically and tick Keep automatically:
    • after log-in, waiting N minutes (0–240, default 15) — for machines switched off at night;
    • daily at HH:MM — for machines left on or asleep.

The status line shows the last copy (files copied and unchanged, space used, free space, growth rate), the schedule and the folder the automatic job writes to. Saving a new folder or mode moves the installed job to it. Remove keeper removes the automatic job and the setting; kept files are never deleted.

8. Schedules and what each platform installs

PlatformScheduler entry (one per user)
macOSlaunchd user agent ~/Library/LaunchAgents/app.codedelta.logkeeper.plist. After log-in: RunAtLoad. Daily: StartCalendarInterval.
WindowsTask Scheduler task CodeDeltaLogKeeper. After log-in: /SC ONLOGON. Daily: /SC DAILY /ST HH:MM.
LinuxA line in the user's crontab tagged # app.codedelta.logkeeper. After log-in becomes @reboot (after start-up). Daily: M H * * *.

The wait after log-in is carried in the job's command as --wait N. Installing a schedule replaces any earlier keeper job for that user.

Daily runs and power state. launchd starts a job whose time passed while the Mac was asleep when it wakes, but a run whose time passed while the machine was switched off is not made up. For machines that are shut down outside working hours, use the after-log-in schedule.

9. Command line

The program: macOS /Applications/CodeDelta.app/Contents/Resources/codedelta-gui/codedelta-gui; Windows C:\Program Files\CodeDelta\codedelta-gui.exe (default install folder); Linux codedelta-gui in the extracted bundle. Below, codedelta-gui stands for that path.

# copy now codedelta-gui scan "<keep folder>" --mode tracer-keep --compact # install: N minutes after log-in (default 15; 0–240) codedelta-gui scan "<keep folder>" --mode tracer-keep --compact --install-at-login --delay 15 # or install: daily at a set time (default 03:00; --hour H also accepted) codedelta-gui scan "<keep folder>" --mode tracer-keep --compact --install-nightly --at 03:00 # remove the scheduled job (kept files are not touched) codedelta-gui scan "<keep folder>" --mode tracer-keep --remove-nightly
OptionEffect
--compactStrip base64 runs of 2,000+ characters (images, snapshots).
--no-compressStore copies uncompressed.
--keep-from DIRCopy that folder instead of this machine's agent folders.
--wait NWait N minutes before copying (used by the after-log-in job).

Exit code 0: the run completed. Exit code 2: refused or failed (protected folder, disk floor, unmounted volume, unreadable manifest, files not kept, invalid schedule), with the reason on standard error.

10. Deploying to many machines

The scheduled job is per user: it is installed in the user's own scheduler and copies that user's logs. Deploy the application as usual, then run the install command in the context of each user (not as root or SYSTEM), for example from your device-management tool's user-context script or a log-in script:

# macOS, run as the logged-in user "/Applications/CodeDelta.app/Contents/Resources/codedelta-gui/codedelta-gui" \ scan "$HOME/tracer logs" --mode tracer-keep --compact --install-at-login --delay 15 # Windows, run in the user's context "C:\Program Files\CodeDelta\codedelta-gui.exe" scan "%USERPROFILE%\tracer logs" --mode tracer-keep --compact --install-at-login --delay 15 # Linux, run as the user ./codedelta-gui scan "$HOME/tracer logs" --mode tracer-keep --compact --install-at-login --delay 15

The same command with --remove-nightly removes the job. The keeper writes to a folder and has no network code; to collect copies centrally, point the keep folder at a location your existing backup or file-collection tooling already gathers.

11. Checking that it runs

WhatWhere
Output of each scheduled runlogkeeper.log in the CodeDelta settings folder: macOS ~/Library/Application Support/CodeDelta/; Windows %APPDATA%\CodeDelta\; Linux ~/.config/codedelta/
Outcome of the last command-line or scheduled runlogkeeper-last.json in the same folder: time, ok, the problem if any, files copied, unchanged and not kept
History of every runruns in codedelta-keep-manifest.json in the machine folder
At a glanceThe Log keeper status line in the app; a failed automatic run is shown first, with its reason

12. Reading the kept logs

A keep folder is a normal AI Agent Tracer input. Select it as the agent-logs folder in the app, or run:

codedelta-gui scan "<keep folder>" --mode tracer --out-dir <report folder>

The report reads the compressed files directly and states in its header that it was produced from a keep folder and the date the copies run to. A keep folder holding several machines' subfolders produces one report across all of them.

13. Limits of this version

Keep a copy of this guide

The same document as a PDF, for your runbooks.