What an agent can see
An agent can receive data from several sources, subject to its configuration and permissions:- Run input and conversation context
- Tools, integrations, and knowledge bases available to the agent
- Credentials bound to the agent
- Prior state or history supplied to the run
- Model and tool responses returned during the run
Automatic credential masking
The KAOP SDK masks exact occurrences of credentials delivered to a run before reporting run output, events, diagnostics, and saved state. For example, if a tool echoes an API token in a response, the matching value is replaced with a redaction marker in the data emitted through the SDK.Redaction with guardrails
Standards and guardrails can inspect, block, or redact governed traffic at configured model and tool gateways. KAOP includes detectors for common sensitive values such as payment card numbers, US Social Security numbers, email addresses, private keys, JWTs, and several cloud and SaaS credential formats. You can also define patterns for data specific to your organization. Guardrails apply only at the gateway stages you configure. A direct network call made by custom agent code does not pass through a KAOP gateway automatically.Reduce data before it leaves the source
The strongest control is to avoid collecting unnecessary data:- Give the agent only the tools, credentials, and resources required for its task.
- Filter and aggregate data close to the source.
- Return findings and references instead of raw logs or full records.
- Apply guardrails at model requests, model responses, tool calls, and tool responses where the associated gateway is used.
- Review run evidence to confirm that the agent emits only what you expect.
Management APIs do not reveal stored secrets
Credential management surfaces can create, replace, disable, bind, and delete credentials, but do not return stored values. Plaintext is available only during authorized delivery to a worker or run. See Credentials & secrets for the delivery modes and lifecycle controls.Next steps
Data retention, deletion & export
What happens to evidence after KAOP stores it.
Standards & Guardrails
Configure inspection, blocking, and redaction at governed gateways.
Secrets & credential handling
Understand credential storage, binding, and delivery.
Network & egress control
Decide which traffic can leave the worker environment.
Runs & evidence
Review the record created by an agent run.