Operational visibility

What Happened In This AI Session?

Follow one request ID through turns, model calls, tools, routing decisions, guardrails, latency, estimated cost, and the retained trace.

What this answers

Transcript

At twelve forty-one, a clinician's AI assistant completed its task. The response looked successful, but the session took forty-four point two seconds, called two tools, touched patient data, and triggered a policy. The alert alone cannot explain that chain. The platform team needs to know what actually happened. Start with the request ID already present in the alert or application log. In PrivacyFirst Activity, paste it into Jump to request. The exact record opens with its correlated conversation and turn, while the time window stays in the destination. There is no manual join across provider logs, application events, tool telemetry, and policy records. Before opening any individual span, the session summary sets the scope. This was three turns, five model requests, and eleven connected spans over forty-four point two seconds. It used five thousand three hundred and five tokens, with four cents of estimated model cost. Two personal-data detections and one policy event are already attached to the same session. A flat request list cannot explain an agent. The session trace aligns turns, model calls, tool actions, guardrails, and accumulating cost on one clock. You can see the patient-summary lookup in the first turn, then the interaction checker inside the second. The order matters: it shows which model call led to a tool, what returned afterward, and where time and cost accumulated. Now isolate the slow model step. Its request record identifies the selected model, a measured latency of five thousand eight hundred and twenty-five milliseconds, eight hundred and seventy-six tokens, a successful status, and the estimated cost. The routing record explains why it was slow. The primary target was throttled after nineteen hundred milliseconds. PrivacyFirst used the approved failover path, and the second target succeeded in thirty-nine hundred and twenty-five milliseconds. One provider throttle was absorbed, and the end-user request still completed successfully. The final turn carries a different kind of exception: the privacy decision. The request shows two personal-data detections, the enforcement-decision link, and the redaction action. When the operator opens retained content, the body is still redacted server-side. The replacement markers make that visible without exposing patient data. The interface also states the active retention period, and every retained-body read is audited. The investigation now has a defensible answer. This was a three-turn session. The second turn called the interaction checker. A provider throttle made one model step slow, but the approved failover recovered it. The final request carried two personal-data detections and a redaction decision. One deep link preserves the conversation, selected evidence, and time window so platform and security teams review the same governed trace. Bring us one hard-to-explain AI session. We'll show you the governed path behind it. Book a live demo at PrivacyFirst dot AI.