> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tolmo.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Review agent run history

> List existing Red and Blue Agent runs and inspect Blue Agent execution details from the CLI.

Use the CLI to review completed and active runs for your organization.

## List runs

```bash theme={null}
tolmo red-agent runs --days 7 --run-status completed --json
tolmo blue-agent runs --days 7 --severity high,critical --json
```

Both commands support these filters:

| Flag | Behavior |
| - | - |
| `--days` | Runs started in the last N days |
| `--severity` | Comma-separated severities |
| `--run-status` | Comma-separated `running`, `completed`, or `failed` values |
| `--limit` | Page size from `1` to `200`; defaults to `100` |
| `--offset` | Number of matching runs to skip; defaults to `0` |

Each JSON response contains `items` and `total`. Increase `--offset` to retrieve subsequent pages.

Blue Agent also supports `--scope` for comma-separated target hostnames and `--search` for a run ID or workflow ID.

## Inspect a Blue Agent run

```bash theme={null}
tolmo blue-agent runs show <run-id>
tolmo blue-agent runs show <run-id> --json
```

The identifier can be a scan ID, a `RUN-` prefix, or a workflow ID. The detail view shows the run's execution stages. A completed run does not by itself mean a finding was confirmed; review the result and the linked [finding](/commands/findings).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.