Audit logs without file names: what to log for Sume jobs
Claude's Compliance API Activity Feed stopped returning file names. For Sume jobs, log request ids and job ids, never media URLs or transcripts.

Claude platform release notes for September 24, 2026 say the Compliance API Activity Feed no longer returns file names, project document names or artifact titles, and those fields are always empty or omitted. The lesson for Sume jobs is the same: build audit logs from ids and statuses, not from content.
What changed upstream
The release notes, read on 2026-10-03, describe the change on the Activity Feed. If you built a report that joined on a file name, it now has nothing to join on. Whatever the vendor's reasoning, an audit trail that depends on content fields is fragile.
What Sume says is safe to log
Sume's safe automation guidance separates safe and unsafe log fields. Follow it as written.
| Safe to log | Unsafe to log |
|---|---|
| Request ids | API keys |
| Job ids, when needed | Signed URLs |
| High-level status | Raw private media URLs |
| Sanitized media metadata | Excessive user content or transcripts |
Why request ids are enough
Every error body includes a request id that is safe to share with Sume support, and the same id is exposed in response headers. Support can resolve an issue from that id without your API key, signed URLs or workspace ids, so those never belong in a ticket or a log line.
import json, logging
log = logging.getLogger("sume.audit")
def log_submit(response, intent):
body = response.json()
err = body.get("error", {})
record = {
"intent": intent,
"http_status": response.status_code,
"job_id": body.get("id") or body.get("request_id"),
"error_code": err.get("code"),
"request_id": err.get("request_id"),
}
log.info(json.dumps(record))Keep the content elsewhere
If you need to know which file a job produced, store a mapping in your own database from job id to your internal asset key, with access controls of your choosing. The log then holds only ids, and the sensitive content lives in a store you can restrict, expire and delete on your own schedule.
Job webhooks need the same care
Webhook payloads carry artifact URLs. Log the job_id and event, not the body. Sume's docs also say to use job_id as your idempotency key on the receiving side.
Sources
Related posts
More in Developers
- Backgrounded MCP tool lost progress: resume with Sume jobs_wait
A Claude Code fix covers MCP progress dropped when a tool moves to the background. Do not rely on progress for Sume jobs: re-issue jobs_wait in slices.
- Basin Pipelines: log Sume webhook deliveries and dedupe by job_id
Cloudflare Basin Pipelines streams ingest up to 1 GB/s. Log each signed Sume webhook delivery as one record and dedupe on job_id; Python sketch included.
- Blind-test Sonic 3.6 against 3.5 on your own script
A vendor's blind-test percentage is not yours. Render the same lines with two catalog versions through the TTS Router, shuffle them, and let listeners vote.
- Browser voice app that starts Sume jobs: keep the key on your server
Voice apps run in the browser over WebRTC, but Sume keys belong on a server. A route handler that holds the key, allowlists models, reuses idempotency keys.
Written by Sume