Agent Trace permissions
Last updated: September 9, 2026
Span provides four Agent Trace permissions:
Agent Trace Data
Agent Trace Contents
Agent Trace Reporting
Manage Traces
Each permission is scoped: you grant it per person or per team, not org-wide. Someone with a trace permission sees traces belonging to the people and teams they have been granted, not everything in the organization. Agent Trace Data and Agent Trace Reporting can be granted at both the team and the individual level; Agent Trace Contents and Manage Traces are individual-level only.
By default, trace contents are visible only to the engineer who authored the trace. Prompts, agent responses, and transcripts are not shareable through permissions at all under the default policy. Everything else about a trace, including cost, model usage, and evaluation scores, is shareable through the permissions below.
If you want to change that default and manage trace contents through RBAC instead, reach out to your Span representative.
1. Agent Trace Data
Provides visibility into trace metadata: the trace list, cost and model usage, duration and activity counts, evaluation scores, and rolled-up trace metrics. It also unlocks the pages built on that metadata, such as AI Effectiveness Overview, the Traces page, AI investment, and Task classification.
It does not include prompts, trace conversations, eval summaries, the reasoning behind each eval score, or the trace title. Traces appear in the list with a placeholder identifier instead of their title.
The reason titles, eval summaries, and eval reasoning are excluded is that they are generated from the session itself, so trace contents can leak into them.
This permission must be granted together with Agent Trace Data for the same people: both are required to read a given person's trace contents.
2. Agent Trace Contents
View the trace itself: the prompts, agent responses, tool calls, and turn-by-turn transcript. It also reveals the parts of the metadata that are generated from the session—the trace title, the eval executive summary, and the reasoning and citations behind each eval score.
This permission is not available by default, unless your organization has moved trace contents to RBAC (see above). Under the default policy, contents stay restricted to the trace’s author.
3. Agent Trace Reporting
View the insights layer built on top of traces, including the Environment Readiness report and recommended improvements derived from trace analysis. This permission is granted independently, so your team can view the Environment readiness report without exposing individual traces.
Granted on its own, recommendations are readable but the traces behind each recommendation are not visible. Pair it with Agent Trace Data if you want people to be able to drill from a recommendation into the sessions that produced it.
4. Manage Traces
Delete traces belonging to the people you have been granted this permission for. Granted alongside Agent Trace Data. Deleting a trace also removes any linked sub-sessions captured as part of it.