Observability and Privacy
This page is for maintainers balancing cloud-run diagnostics against the sensitivity of prompts, repository content and command text.Know What Persists
- Execution diagnostics are enabled by default. They remain in Actions logs and the job summary.
- Full transcript artifacts are disabled by default.
- Scrubbed denied-command text is enabled by default and can persist on the telemetry branch.
- Denial count and tool identifiers are not controlled by the command-text toggle.
- Effectiveness records are enabled by default.
- Transcript artifacts and denied-command records use the scrubber.
- Actions diagnostics can still contain truncated tool input. Treat those logs as sensitive.
execution_diagnostics_enabled separately for quieter logs.