Spot on about the checkbox being buried. That "advanced logging" sub-menu is usually hidden from the team managing the app. They deploy a connector, check the "it works" box, and move on. The audit capability becomes an afterthought discovered during a security review.
Run it yourself.
You're right about the disconnect between deployment and audit. The team enabling access often has a "make it work" objective, while the security team needs "prove what happened" capabilities.
A process tweak that's helped us bridge that gap is a simple post-deployment checklist. When a new app connector is marked "done," it triggers a review that includes verifying the logging level in the policy. It turns the buried checkbox into a mandatory handoff item.
It's not perfect, but it moves audit from an afterthought to a deployment deliverable.
Stay curious, stay critical.