Redaction overview
Learn what redaction keeps out of your telemetry, where it runs, and how withheld content looks when you read a trace.
Redaction keeps chosen content out of the telemetry your application sends to AIO. Use it for content you don't want stored, such as a proprietary system prompt, a generated query, or a secret a customer pasted into a chat.
Redaction changes only what AIO records. Your model still gets the full request. If you want to change what the model receives, use Guard instead.
What redaction withholds
A redaction policy can do any of the following:
- Replace system instructions and tool definitions with a fingerprint, so you can still tell prompt versions apart. See Hide system prompts and tool definitions.
- Withhold the arguments or results of the tools you name. See Redact tool arguments and results.
- Scrub text that matches regular expressions, and let specific matches through. See Redact by pattern.
- Withhold named attributes, or leave whole spans out of a trace. See Drop attributes and spans.
Off by default
Every redaction setting is off by default. Until you turn on at least one setting, AIO records content as your application sends it.
Turn on redaction in the Python SDK in one of these ways:
- Pass a policy built with
aio.redaction_policy(...)to theredactionparameter ofaio.init. - Set environment variables. AIO reads them only when you don't pass a policy to
aio.init. These variables are off by default too.
How it works
The following diagram shows what stays inside your application and what reaches AIO when redaction is on.
- You set a policy. Call
aio.initonce, at startup, before you create any HTTP or model clients. The policy applies to every instrumentation in your application's process. - Your application calls the model as usual. Redaction never changes the request, so the model gets the full prompt, the tool arguments, and the messages.
- The SDK applies the policy inside your application. Spans and log records are redacted as they leave your process, before anything is sent to AIO. Withheld content never leaves your application.
- You read the redacted trace in AIO. Open a trace and the detail pane for one of its steps. Withheld content shows a fingerprint or a placeholder where the original value was. For how to find and open traces, see Explore traces.
Important
If AIO can't enforce your policy, aio.init raises RedactionUnavailable and telemetry doesn't start, so unredacted content is never sent. One cause is an OpenTelemetry tracer provider your application set up before it called aio.init. Call aio.init() before you configure OpenTelemetry.
How withheld content appears
Withheld content is replaced, not deleted. That way you can tell content that was withheld from content that was never captured. You'll see one of two values:
Value | What it looks like | When you see it |
Fingerprint |
| A whole value was withheld, such as a system prompt, a tool definition, or a tool's arguments or results. |
Placeholder |
| Text matched a pattern, the SDK couldn't read the content, or an error occurred during redaction. |
The fingerprint is a SHA-256 hash of the original value. The same value always gives the same fingerprint, so you can see whether two runs used the same prompt without seeing the prompt.
On the step detail pane:
- System instructions. This block is collapsed by default. When the prompt was replaced by its fingerprint, the header reads System instructions and 71 characters. Expand the block to see the message "Only the prompt's fingerprint was exported — the text itself was not captured." No Copy button appears.
- Input and Output. Previews show withheld values as they were stored. For example, a tool step's input preview shows the arguments'
sha256:fingerprint, and scrubbed text shows__REDACTED__.
If an error occurs while a span or log record is being redacted, AIO withholds that record's prompt, messages, tool definitions, and tool arguments and results, and replaces them with __REDACTED__. The step still shows its timings, token counts, and identifiers.

Have a suggestion?