1
Curious builder0 XP earned · 300 to level 2
0 daysFinish a lesson to begin
Badge collection0 of 6 unlocked
51 small wins to finish your pathNext question →
How should prompts, outputs and traces be governed in terms of retention and access?
30-second answerSay your answer out loud first, then reveal.
Policy example
| Data | Retention | Access |
|---|---|---|
| Aggregated metrics (tokens, latency, costs) | 2 years | Engineering, finance |
| Trace metadata (no payload) | 90 days | Engineering |
| Redacted payload samples | 30 days | AI team (need-to-know) |
| Raw payloads for flagged incidents | Per incident policy | Restricted, audited |
| Eval datasets from production | Until superseded; consented / anonymised | AI team |
Also consider
- User deletion requests: find and delete across logs, caches, eval sets and fine-tuning datasets (lineage needed).
- Provider-side retention: enterprise settings for zero or limited retention.
- Data residency: logs stored in the required region.
- Training on logs: only with consent and policy approval.
Related
Every expert started right here.