Currently there is an activity log when restores are done. But the key piece of information missing is: "who done it?" This may be difficult if the restore is initiated through the Agent console but if done via RedApp or SP Console/InstantData, then there is a user associated with the process.
Surely it is beneficial to be able to audit who is restore customer data?!! My suggestions would be the following:
If Agent Console is launched from SP Console then the SP Console login user should be tracked
If launched from RedApp then RedApp user should be tracked
If Agent Console is launched then InstantData initiated, the Windows login user should be tracked.
This information may not be perfect, but it is certainly not better than 🤷♂️