For teams that want visibility into how their agents are performing, that creates a real question: how do you get the insights you need without accumulating data you didn't intend to store?

The answer depends on what controls the observability platform gives you. Here's how Pendo approaches it.

When you do store data, you control what gets redacted, per agent

Most tools that offer PII redaction apply one rule set across your entire account. But because customer support bots handling billing disputes and internal onboarding assistants have different data requirements, you’re either over-protecting one or under-protecting the other.

To fix this, Pendo scopes redaction controls per agent. AI Agent Admins and Pendo Admins can configure which of 14 sensitive-data categories get redacted for each agent, directly in the product, without involving engineering. Those categories include:

  • Names
  • Email addresses
  • Phone numbers
  • Physical addresses
  • Dates
  • Social Security Numbers (SSN)
  • National IDs
  • Tax IDs
  • Credit/debit card information
  • Bank account details
  • Invoices
  • Currency amounts
  • Usernames
  • IP addresses

All 14 are on by default, so your account starts with the strictest available configuration from day one, no setup required. From there, teams can adjust to fit each agent's actual use case.

When content is redacted, users see a typed placeholder — [NAME], [EMAIL] — in Conversations and Prompts. That way, conversations stay interpretable without exposing the original value.

Everything is protected by default

Unlike tools where privacy controls are opt-in, Pendo enables all 14 redaction categories by default. Your account starts with the strictest available configuration the moment you add an agent, eliminating any setup window where data is exposed while someone figures out what to enable.

From there, the controls are yours. Tighten settings for agents handling the most sensitive interactions, or loosen them where the defaults remove more context than your team needs. Either way, it's an intentional choice you deploy for each agent.

You don't have to store raw conversation data (coming soon)

For some teams, the blocker is that raw conversation data gets stored at all. Others can't let prompt data be tied back to individual visitors. Until now, those teams couldn't use Agent Analytics.

With zero-day retention, Pendo processes prompts and responses into aggregate metrics, use cases, and issues, then deletes the raw content. You get the full Agent Analytics picture without carrying data residency risk.

Visitor de-identification gives teams a second layer of control: anonymize visitor IDs in Agent Analytics so that conversation data can't be traced back to individual users. Visitor IDs elsewhere in Pendo stay unchanged. Both are opt-in and set when tagging your agent.

Insights and data protection aren't a tradeoff

The assumption that measuring AI agent performance requires retaining raw conversation data isn't true; it depends on the platform.

Custom redaction gives teams control over what gets stored and how sensitive content is labeled, per agent, without engineering. Zero-day retention and visitor de-identification handle cases where raw storage isn't an option.

Together, they're designed to make Agent Analytics work easily for how your organization handles data.

Learn more about Agent Analytics →