Agent run log allowlist: which Sume fields are safe to keep

Log request ids, job ids, status and sanitized media metadata from Sume agent runs; never log API keys, signed URLs, raw private media URLs or full transcripts.

5 min readSume
All posts

For Sume agent runs, log the request id, the run id, job ids when needed, the high-level status, the usage amounts and sanitized media metadata. Do not log API keys, signed URLs, raw private media URLs, or large chunks of user content such as transcripts. That is the split the Safe automation page gives.

The run receipt is a good source because most of what you want is already in it, and output.images, output.videos, output.audio and output.files carry durable media.sume.com HTTPS URLs rather than short-lived signed ones.

Field by field

Mapped to the receipt fields in the Agent Completions and Runs pages, read 2026-10-09.

Receipt fields and logging policy
FieldLog it?Note
id / run_id (agrun_...)YesDedupe key; the webhook request_id equals it
statusYesqueued, processing, completed, failed, canceled
usage.billable_amount_usd_microsYesnull when spend could not be read
usage.generation_spend_cap_usd_microsYesShows the cap that applied
output.textCarefulMay hold user content; truncate or hash
media.sume.com URLsYesDurable public ids
Signed URLsNoExpire and grant access
API key, bearer tokenNeverRotate if seen

Webhook receivers

Log the envelope's event, request_id, status and outcome, and the x-sume-webhook-secret-fingerprint header, which lets you compare secrets without sending the secret anywhere. Do not log the signing secret or the raw signature header with the body together if your logs are widely readable.

Branch on outcome rather than status alone: a run can complete and bill you but project no structured output, which shows as degraded.

Why this is worth being strict about

Agents are good at repeating what is in front of them. A key that lands in a log line can reappear in a later prompt, and a signed URL is a bearer link to private media. An allow-list of fields is easier to review than a deny-list of patterns, and it makes an incident review simple: with run ids and statuses in hand you can reconstruct what happened without needing the content.

Example log line

A useful line for a finished run holds the run id, the status, the outcome, the billed amount in USD micros, the cap that applied and the count of generated files. For example, a run that billed 240,000 micros under a 1,000,000 micro cap spent $0.24 of a $1.00 cap. That one line answers whether the cap was close, whether the run produced anything, and which run to open if someone asks, without carrying a single URL or word of user content.

Keep the full receipt out of general logs. If you must retain it for audits, store it in a place with tighter access than application logs, and keep retention short. If you export logs to a third-party tool, apply the same allow-list at the exporter, so a later change in one place cannot widen what leaves your systems.

Sources

Related posts

More in Agents

All Agents posts

Written by Sume