Skip to main content
The Komodor Agentic Operation Platform (KAOP) records the inputs, outputs, and evidence that an agent emits so you can understand its work. Access controls decide what the agent can reach; credential masking and guardrails reduce what sensitive data appears in that record. These controls have different boundaries, so use them together.

What an agent can see

An agent can receive data from several sources, subject to its configuration and permissions:
  • Run input and conversation context
  • Tools, integrations, and knowledge bases available to the agent
  • Credentials bound to the agent
  • Prior state or history supplied to the run
  • Model and tool responses returned during the run
KAOP does not copy every source record merely because an agent can read it. Data becomes part of a run record when the agent, SDK, model, or tool emits it as input, output, an event, evidence, or saved state.

Automatic credential masking

The KAOP SDK masks exact occurrences of credentials delivered to a run before reporting run output, events, diagnostics, and saved state. For example, if a tool echoes an API token in a response, the matching value is replaced with a redaction marker in the data emitted through the SDK.
No rule is required for credential masking, but it is not a general data-loss-prevention system:
  • Encoded, hashed, split, truncated, or otherwise transformed values may no longer match the original credential.
  • Personal or business data that is not a delivered credential is not automatically masked by this mechanism.
  • Custom code that sends data outside the SDK reporting path is outside this protection.
  • A value already delivered to a running process remains available to that process until its lifecycle ends.
Do not put credentials in prompts, logs, tool arguments, or saved state. Automatic masking is a backstop for accidental disclosure, not permission to expose or forward a secret.

Redaction with guardrails

Standards and guardrails can inspect, block, or redact governed traffic at configured model and tool gateways. KAOP includes detectors for common sensitive values such as payment card numbers, US Social Security numbers, email addresses, private keys, JWTs, and several cloud and SaaS credential formats. You can also define patterns for data specific to your organization. Guardrails apply only at the gateway stages you configure. A direct network call made by custom agent code does not pass through a KAOP gateway automatically.

Reduce data before it leaves the source

The strongest control is to avoid collecting unnecessary data:
  1. Give the agent only the tools, credentials, and resources required for its task.
  2. Filter and aggregate data close to the source.
  3. Return findings and references instead of raw logs or full records.
  4. Apply guardrails at model requests, model responses, tool calls, and tool responses where the associated gateway is used.
  5. Review run evidence to confirm that the agent emits only what you expect.
For example, prefer an output such as “three workloads use the affected image” with links to the workloads over copying the complete workload specifications into the run record.

Management APIs do not reveal stored secrets

Credential management surfaces can create, replace, disable, bind, and delete credentials, but do not return stored values. Plaintext is available only during authorized delivery to a worker or run. See Credentials & secrets for the delivery modes and lifecycle controls.

Next steps

Data retention, deletion & export

What happens to evidence after KAOP stores it.

Standards & Guardrails

Configure inspection, blocking, and redaction at governed gateways.

Secrets & credential handling

Understand credential storage, binding, and delivery.

Network & egress control

Decide which traffic can leave the worker environment.

Runs & evidence

Review the record created by an agent run.