What you will be able to do
- Decide which content gates to enable, weighing debugging value against privacy and telemetry volume
- Explain how managed settings pin the OTLP destination, and what they do not lock
- Use prompt.id and collector-side redaction when streaming organisation-wide Cowork events
- Pick between a real-time OpenTelemetry stream and the daily Analytics API for a monitoring need
1.Content gates: what telemetry reveals by default
By default, Claude Code telemetry records that something happened, not what it contained. Prompt text on the interaction span is redacted until you opt in. For example, the user_prompt attribute reads <REDACTED> unless OTEL_LOG_USER_PROMPTS is set. Each extra layer of content has its own gate, so you can turn on exactly as much detail as an investigation needs.
| Variable | Adds | Condition or caveat |
|---|---|---|
| OTEL_LOG_USER_PROMPTS=1 | Prompt text on claude_code.user_prompt events and on the claude_code.interaction span | Off by default |
| OTEL_LOG_TOOL_DETAILS=1 | Tool input arguments (file paths, shell commands, search patterns) on claude_code.tool_result events | Off by default |
| OTEL_LOG_TOOL_CONTENT=1 | A tool.output span event on claude_code.tool with file contents, Bash output and MCP, WebFetch and WebSearch results | Requires tracing to be enabled; truncated at 60 KB by default |
| OTEL_LOG_RAW_API_BODIES | Full Messages API request and response JSON as claude_code.api_request_body and claude_code.api_response_body log events | 1 for inline bodies, or file:<dir> for untruncated bodies on disk; implies consent to the three gates above |
The last row carries the most data. Raw bodies include the entire conversation history, with extended-thinking content redacted. Turning them on therefore exposes everything the narrower gates would expose. Volume is the other cost. CLAUDE_CODE_OTEL_CONTENT_MAX_LENGTH caps content-bearing attributes at 61440 UTF-16 code units (60 KB) by default. That default is sized for backends that cap attribute values at 64 KB. Raise it only if your backend accepts larger values, and lower it when telemetry volume becomes the problem.
2.Pinning the collector with managed settings
(Answer to the prediction: no. Tool content is a span event on claude_code.tool, so it needs tracing.) Across many developer machines, the next risk is telemetry going to a collector the organisation didn't choose. Managed settings handle this by removing conflicting developer-set values. If you set OTEL_EXPORTER_OTLP_ENDPOINT, every per-signal endpoint a developer set is removed. OTEL_EXPORTER_OTLP_PROTOCOL works the same way. If you set credentials (OTEL_EXPORTER_OTLP_HEADERS or the client key or certificate), Claude Code also removes every developer-set endpoint, so those credentials can't be sent to another collector.
Exporter selectors are different. OTEL_METRICS_EXPORTER, OTEL_LOGS_EXPORTER and OTEL_TRACES_EXPORTER follow normal per-key precedence. That means a developer can still switch a signal off or move it to the console exporter unless the selectors are also set in managed settings. When detailed beta tracing is active, logs and traces go to BETA_TRACING_ENDPOINT, and managed settings remove a developer-set value there too whenever they decide either signal's destination.
No. The endpoint and credentials are locked, but the exporter selector follows normal per-key precedence, so the developer's none disables the logs signal. To enforce export, set the selector in managed settings as well.
Sources2
3.Organisation-wide event streams: Claude Cowork
On Team and Enterprise plans, an admin can stream Claude Cowork activity across the whole organisation to an OTLP collector. It is set up under Organization settings > Cowork with an endpoint, the HTTP/JSON or HTTP/protobuf protocol, and authentication headers. Nothing is exported until an admin configures an endpoint. The stream covers user prompts, file access, skills and plugins, API requests and errors, human approval decisions, and tool and MCP invocations.
Two properties shape how you use this stream. First, correlation: a shared prompt.id attribute links every event triggered by one user prompt. When investigating an incident, you pivot on prompt.id to reconstruct everything Claude did in response to one input. Second, the defaults are the reverse of the SDK's. In Cowork, prompt text is included by default, tool_parameters can carry file paths and command arguments, and user email addresses are attributes on events. Redaction therefore happens in your collector, before events are routed on to downstream destinations. One collector can also send events to several destinations at once, such as a SIEM like Splunk and an observability platform like Datadog.
Sources3
4.Choosing the right monitoring mechanism
Not every monitoring question needs a live telemetry pipeline. The documentation offers mechanisms with very different freshness and scope. For a single application, the SDK message stream already carries token and cost data without any backend. For organisation-wide adoption and spend, the Analytics APIs return aggregated reports rather than events.
| Need | Mechanism | Caveat |
|---|---|---|
| Debug why one agent turn was slow | OpenTelemetry traces | Beta; needs the enhanced telemetry flag |
| Security monitoring and incident investigation across users | Cowork OpenTelemetry stream to a SIEM | Prompt content and emails included; redact at the collector |
| Daily Claude Code productivity per user on the Claude Platform | Claude Code Analytics API (Admin API key) | An Admin API key cannot call the Enterprise Analytics API |
| Org-wide engagement, connector usage and cost on Claude Enterprise | Claude Enterprise Analytics API (Analytics API key) | Engagement data lags about a day; cost values can be revised for 30 days |
The Analytics API caveats catch people out. Cost and usage data usually arrives within four hours but can take up to 24, and a date's values can change for up to 30 days as late events are reconciled. For invoicing-grade totals, query dates at least 30 days in the past. There are also coverage gaps. Claude Code used through Amazon Bedrock doesn't appear in the Enterprise Analytics API, which is one reason a team might run an OpenTelemetry stream alongside it.
An organization is scaling its Claude Code rollout from 15 developers to roughly 300 developers and wants to set organization-level Tokens-Per-Minute and Requests-Per-Minute allocations. A junior admin proposes simply multiplying the 15-user TPM-per-user figure by 300. Why is this the wrong approach, and what should the admin do instead?
Correct answer: A — Per-user TPM/RPM shrinks as org size grows since fewer users are concurrently active at scale, so the admin should multiply by the lower per-user figure for the 300-user tier, not the 15-user figure
- A. Correct. The documented guidance shows per-user TPM and RPM recommendations decreasing as team size grows (e.g. 200k-300k TPM/user at 1-5 users down to 10k-15k TPM/user at 500+ users) because concurrent usage doesn't scale linearly with headcount, so scaling from the 15-user tier's figure would drastically over-provision.
- B. The recommendation table explicitly decreases per-user TPM and RPM as organization size increases; treating it as flat leads to requesting far more capacity than the organization will concurrently use.
- C. Rate limits apply at the organization level, not per individual user, which is precisely why naive per-user multiplication overstates the real requirement and why aggregate, tier-aware planning matters.
- D. The TPM/RPM sizing guidance applies broadly to planning Claude Code capacity for teams regardless of which provider handles the underlying API traffic, so it cannot be dismissed for Console-authenticated organizations.
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.OpenTelemetry export from Claude products never contains prompt text unless someone opts in, so a new Cowork stream is safe to route straight into the SIEM.Why is that wrong?
The Agent SDK and Claude Code redact prompts by default, but Cowork includes prompt content in events by default. Filtering or redaction has to be configured in the collector.
2.Yesterday's cost figures from the Enterprise Analytics API are final and can be used for invoicing.Why is that wrong?
Cost values can be revised for up to 30 days while late events are reconciled. Invoicing-grade totals should use dates at least 30 days old.
Covered in Choosing the right monitoring mechanism
3.Pinning the OTLP endpoint and headers in managed settings guarantees every signal is exported.Why is that wrong?
Endpoint and credentials are locked, but exporter selectors follow normal per-key precedence. A developer can still disable a signal unless the selectors are managed too.
Covered in Pinning the collector with managed settings
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.
“Enabling this implies consent to everything the three variables above would reveal”
↩︎ Content gates: what telemetry reveals by default“read token and cost data from the message stream without an external backend”
↩︎ Choosing the right monitoring mechanism - 2.https://code.claude.com/docs/en/monitoring-usageOfficial docs
“Value is <REDACTED> unless the gate is set”
↩︎ Content gates: what telemetry reveals by default“raise it only if your backend accepts larger values, or lower it to cut telemetry volume”
↩︎ Content gates: what telemetry reveals by default“when you set OTEL_EXPORTER_OTLP_ENDPOINT, Claude Code removes every developer-set per-signal endpoint.”
↩︎ Pinning the collector with managed settings“can still disable a signal or switch it to the console exporter, so set the selectors in managed settings too”
↩︎ Exam trap 3 - 3.https://support.claude.com/en/articles/14477985-monitor-claude-cowork-activity-with-opentelemetryOfficial docs
“links every event triggered by a single user prompt, so you can reconstruct everything Claude did in response to one input”
↩︎ Organisation-wide event streams: Claude Cowork“You can route events to multiple destinations at once by configuring your collector accordingly.”
↩︎ Organisation-wide event streams: Claude Cowork“User prompt content is included in events by default.”
↩︎ Exam trap 1 - 4.
“If your organization uses Claude Code through Amazon Bedrock, the Claude Enterprise Analytics API does not return Claude Code activity for that usage.”
↩︎ Choosing the right monitoring mechanism“For invoicing-grade totals, query dates at least 30 days in the past.”
↩︎ Choosing the right monitoring mechanism“Values for a given date can be revised for up to 30 days as late events arrive and reconciliation runs.”
↩︎ Exam trap 2