Most difficult agent incidents begin with one question:

Why did the agent do that?

Why did it call this tool? Why did it retry? Why did it skip the notification? Why did it trust stale data? Why was an action blocked even though every API call succeeded?

Traditional logs often answer a narrower question: what executed?

agent started