File history only covers half the problem, because behavior can also change when someone grants a new permission, switches the runtime, or connects another resource. You need configuration and permission changes tied to a clear audit record, with agent activity visible alongside them. You can use an AI agent management tool here https://agyn.io/ . Keep agent definitions under GitOps, apply access controls and tool-call policies, and use the audit logs to see what happened around each release. When behavior shifts, you can tell whether it came from a configuration change, a permission change, or something that happened during execution.