Dashboard
0%
1
Curious builder0 XP earned · 300 to level 2
0 daysFinish a lesson to begin
Badge collection0 of 6 unlocked
51 small wins to finish your pathNext question →

Q15EasyConcept

How should prompts, outputs and traces be governed in terms of retention and access?

30-second answerSay your answer out loud first, then reveal.

Policy example

DataRetentionAccess
Aggregated metrics (tokens, latency, costs)2 yearsEngineering, finance
Trace metadata (no payload)90 daysEngineering
Redacted payload samples30 daysAI team (need-to-know)
Raw payloads for flagged incidentsPer incident policyRestricted, audited
Eval datasets from productionUntil superseded; consented / anonymisedAI team

Also consider

  • User deletion requests: find and delete across logs, caches, eval sets and fine-tuning datasets (lineage needed).
  • Provider-side retention: enterprise settings for zero or limited retention.
  • Data residency: logs stored in the required region.
  • Training on logs: only with consent and policy approval.

Every expert started right here.