## 1
1. The Business Pain Point: The Logs Exist, but the Information Doesn't
We're a five-person team building a SaaS approval system for small and medium-sized enterprises. Backend operation logs have always been recorded: who changed pricing rules, who exported the customer list, who bulk-deleted data. The log table grows every day, but when I ask in weekly meetings "what high-risk backend operations happened last week," nobody can answer immediately.
Breaking it down, there are three problems:
- Too much to review. Thousands of log entries per day—manual browsing is unrealistic, so we only investigate after something goes wrong.
- Can't tell what matters. A single log entry says "User A updated config item config_2841," but understanding what that configuration means requires someone who knows the business to translate it.
- Unclear ownership. Operations says tech should handle it, tech says it's a business operation, and the logs end up as everyone's blind spot.
As a manager, what I care about isn't the logs themselves, but rather that someone reviews them regularly as part of the process, understands them, and risks surface proactively. This is exactly where AI summarization can fit in—but it must be part of the workflow, not a toy.
2. Architecture Design: Three Layers with Separated Responsibilities
The architecture we ended up with is simple, and suitable for small teams to copy directly:
┌─────────────┐ ┌──────────────┐ ┌─────────────┐
│ 日志采集层 │ → │ 摘要生成层 │ → │ 呈现与流转层 │
│ DB + 定时任务 │ │ AI API 网关 │ │ 日报 + 企微群 │
└─────────────┘ └──────────────┘ └─────────────┘- Collection layer: No changes to existing log-writing logic; just bucket the previous day's logs by module (permission changes, data exports, configuration changes, bulk operations) every day in the early morning.
- Summary layer: Each bucket is assembled into a structured prompt, sent to the large model through a unified AI API gateway, producing a three-part summary of "what was done / any anomalies / items that deserve attention."
- Presentation layer: The summary is pushed to a WeCom group as a daily report; high-risk items automatically @mention the responsible person, who is required to reply with confirmation the same day—this step brings AI output into a human collaboration workflow instead of sinking into oblivion after being sent.
3. Key Implementation Steps
- Define risk levels before talking about summaries. Together with operations, we defined three levels: red (bulk deletion, privilege escalation), yellow (large data exports, critical configuration changes), white (routine operations). The AI summary organizes content by level, and red items must appear at the top of the daily report.
- Fix the prompt as a template—no freehand writing. Templates are version-controlled, and changes go through review, to prevent summary criteria from drifting.
- Control context length. At most 200 log entries per call; anything beyond gets aggregated in a second pass. Don't expect to feed everything in one shot.
- Build a "summary–confirmation" loop. For risk items flagged by the AI in the daily report, the responsible person must reply in the group. Within two weeks, this actually helped us stop an accidental bulk export.
- Monthly spot checks. Randomly sample 20 log entries and manually verify the summary accuracy, as the basis for model switching and prompt iteration.
Core invocation pseudocode (Python):
buckets = group_logs_by_module(fetch_logs(yesterday))
for module, logs in buckets.items():
for chunk in split(logs, size=200):
prompt = render_template("daily_summary", module=module, logs=chunk)
resp = gateway.chat(
model="gpt-4o-mini", # cheap and sufficient; use a stronger model for high-risk buckets
messages=[{"role": "user", "content": prompt}],
fallback_model="claude-3-5-sonnet",
)
summary = parse(resp)
if summary.risk_level == "red":
notify_owner(summary, mention=True)4. Why a Unified AI API Gateway Reduces Maintenance Costs
This was the most cost-effective decision in this round of changes. The reasons are straightforward:
- Configure once, apply everywhere. Summarization, risk classification, and anomaly explanation all call models through the same gateway; API keys, timeouts, and retry logic are maintained in one place only.
- Models are swappable. Cheap small models for white buckets, stronger models for red buckets—only the gateway routing configuration changes, with zero changes to business code. If a model raises prices or gets rate-limited, switching a fallback solves it, without waiting for a developer to free up time to modify code—this is substantive protection against scheduling risk for a small team.
- Costs and calls are auditable. The gateway uniformly records the token consumption of every call; monthly costs are visible at a glance, so as a manager I don't have to chase tech asking "how much did we spend on AI this month."
- Permission consolidation. Team members don't each need to hold keys, reducing the attack surface—this itself is a form of risk control.
Without the gateway, five features would mean five sets of invocation code and five keys, and any model-side change would trigger a company-wide investigation—small teams can't afford this kind of hidden maintenance.
5. Results and Reminders
One month after launch, the question in weekly meetings changed from "were there any anomalies last week" to "what's the progress on the red items." The logs didn't increase, but for the first time, the information was actually being seen.
Two reminders: AI summaries will miss things—manual spot checks cannot be skipped; and the value of a summary lies in triggering human action—a daily report without a confirmation loop is just pretty.
If you're also working on a similar AI implementation project, a stable, unified AI API gateway can put your model invocation governance on the right track from day one. You can start here: https://api.thistoken.ai/register
---
Every example in this post runs with a single API key — get yours at https://api.thistoken.ai/register and start in minutes.
Bạn muốn thử Token.AI?
Tạo API Key cấp dự án, bật kênh trong bảng điều khiển và định cấu hình định tuyến, ngân sách và nhật ký kiểm tra.
注册 ThisToken.AI 并获取 API Key