I get nervous issuing API tokens because of how powerful they can be, particularly since some actions are irreversible, and we have to trust in the security of whomever we grant the token to. To help detect abuse, it would be helpful to be able to audit the actions performed by any given API token.