Acceldata
AIO

Last updated: Oct 06, 2026 15:42 UTC

Redaction overview

Learn what redaction keeps out of your telemetry, where it runs, and how withheld content looks when you read a trace.

Redaction keeps chosen content out of the telemetry your application sends to AIO. Use it for content you don't want stored, such as a proprietary system prompt, a generated query, or a secret a customer pasted into a chat.

Redaction changes only what AIO records. Your model still gets the full request. If you want to change what the model receives, use Guard instead.

What redaction withholds

A redaction policy can do any of the following:

Off by default

Every redaction setting is off by default. Until you turn on at least one setting, AIO records content as your application sends it.

Turn on redaction in the Python SDK in one of these ways:

  • Pass a policy built with aio.redaction_policy(...) to the redaction parameter of aio.init.
  • Set environment variables. AIO reads them only when you don't pass a policy to aio.init. These variables are off by default too.

How it works

The following diagram shows what stays inside your application and what reaches AIO when redaction is on.

Your application sends the full, unchanged request to the model provider. Inside your application process, the AIO Python SDK applies the redaction policy to spans and log records. Only the redacted telemetry, with fingerprints and __REDACTED__ placeholders in place of withheld content, is sent to AIO and shown in the AIO UI.

  1. You set a policy. Call aio.init once, at startup, before you create any HTTP or model clients. The policy applies to every instrumentation in your application's process.
  2. Your application calls the model as usual. Redaction never changes the request, so the model gets the full prompt, the tool arguments, and the messages.
  3. The SDK applies the policy inside your application. Spans and log records are redacted as they leave your process, before anything is sent to AIO. Withheld content never leaves your application.
  4. You read the redacted trace in AIO. Open a trace and the detail pane for one of its steps. Withheld content shows a fingerprint or a placeholder where the original value was. For how to find and open traces, see Explore traces.

Trace page with the step detail pane open beside the waterfall, showing the System instructions, Input, and Output blocks

Important

If AIO can't enforce your policy, aio.init raises RedactionUnavailable and telemetry doesn't start, so unredacted content is never sent. One cause is an OpenTelemetry tracer provider your application set up before it called aio.init. Call aio.init() before you configure OpenTelemetry.

How withheld content appears

Withheld content is replaced, not deleted. That way you can tell content that was withheld from content that was never captured. You'll see one of two values:

Value

What it looks like

When you see it

Fingerprint

sha256: followed by 64 hexadecimal characters, 71 characters in all

A whole value was withheld, such as a system prompt, a tool definition, or a tool's arguments or results.

Placeholder

__REDACTED__

Text matched a pattern, the SDK couldn't read the content, or an error occurred during redaction.

The fingerprint is a SHA-256 hash of the original value. The same value always gives the same fingerprint, so you can see whether two runs used the same prompt without seeing the prompt.

On the step detail pane:

  • System instructions. This block is collapsed by default. When the prompt was replaced by its fingerprint, the header reads System instructions and 71 characters. Expand the block to see the message "Only the prompt's fingerprint was exported — the text itself was not captured." No Copy button appears.
  • Input and Output. Previews show withheld values as they were stored. For example, a tool step's input preview shows the arguments' sha256: fingerprint, and scrubbed text shows __REDACTED__.

If an error occurs while a span or log record is being redacted, AIO withholds that record's prompt, messages, tool definitions, and tool arguments and results, and replaces them with __REDACTED__. The step still shows its timings, token counts, and identifiers.

Next steps