Governance without hidden surveillance
AI TokenScope governs company-funded AI access and spending. It should not be configured as a hidden employee-surveillance system.
Our approach
TokenScope is a governance tool for managing company-funded AI access. Used responsibly, it gives organizations visibility into spending and policy compliance without crossing into surveillance of individual work output.
Disclose monitoring to employees
Organizations should inform employees that AI usage is monitored for governance purposes before enabling TokenScope.
Collect only what is needed
Configure the minimum data collection required for your governance goals. Metadata-only mode is available when prompt content review is not needed.
Restrict prompt access by role
Not every administrator needs to see prompt text. Role-based access controls limit who can view prompt content.
Prefer aggregated views
Team and project dashboards surface patterns without requiring review of individual prompts.
Configure retention appropriately
Shorter retention periods reduce exposure. Retention is configurable per workspace.
Start in Observe mode
Begin with full visibility and no enforcement. Introduce policies gradually after reviewing usage patterns.
Prompt visibility by role
The table below shows what each role can see by default. Items marked “Configurable” depend on workspace settings. Items marked “Own only” are visible only for the user's own activity.
| Role | Total cost | Request count | Project attribution | Prompt category | Policy result | Full prompt text | Individual identity |
|---|---|---|---|---|---|---|---|
| Developer | Own only | Own only | Own only | Own only | Own only | Own only | Own only |
| Team manager | Yes | Yes | Yes | Yes | Yes | Configurable | Yes |
| Workspace administrator | Yes | Yes | Yes | Yes | Yes | Yes | Yes |
| Finance user | Yes | Yes | Yes | No | No | No | Yes |
| Security reviewer | No | Yes | Yes | Yes | Yes | Configurable | Yes |
| Auditor | Yes | Yes | Yes | Yes | Yes | No | Yes |
Prompt storage modes
Administrators choose how prompt content is stored. The choice affects classification capability, audit search, and employee privacy exposure.
Full content
Request metadata and prompt text are stored per the configured retention period.
Default mode. Enables audit-trail search and classification review.
Metadata only (Privacy Mode)
Team plan or abovePrompt text is never stored. A cryptographic hash is recorded for audit continuity.
Configurable per workspace in Settings. Recommended for workloads involving sensitive information where prompt review is not required.
Retention
Retention periods control how long usage data is kept. Shorter retention reduces data exposure. Longer retention supports compliance and historical reporting.
Free
30 days
default
Startup
90 days
default
Team
1 year
default
Business
2 years
default
Data deletion on request. Customers can request deletion of their workspace data at any time by emailing hello@aitokenscope.com.
Configurable retention. Business and Enterprise plans support custom retention periods shorter than the default.
See the Privacy Policy for the complete data handling and deletion terms.
Auditability
Administrator actions and access to sensitive data are recorded in the audit trail.
Prompt content access
When an administrator views an individual prompt, the access is recorded with the administrator's identity and timestamp.
Administrative actions
Policy changes, user provisioning, role changes, and workspace configuration changes are logged.
Audit record export
Audit logs are exportable for compliance reporting or external review. Available on Startup plan and above.
Audit log retention
Audit logs follow the same retention schedule as usage data and are subject to the same deletion policy.
Implementation checklist
Before deploying TokenScope to a team, work through the following with your legal, HR, and IT stakeholders.
- Inform employees that AI usage through company accounts is monitored for governance purposes.
- Define and document your organization's acceptable-use policy for company-funded AI.
- Select a storage mode — full content for audit search, metadata-only for lower prompt exposure.
- Restrict prompt-text access to roles that have a legitimate governance need.
- Configure a retention period appropriate for your compliance and reporting requirements.
- Start in Observe mode. Review usage patterns before introducing enforcement policies.
- Establish a process for reviewing disputed classification decisions.
- Reassess storage, retention, and enforcement policies periodically as the team grows.
Not legal advice
This page describes product capabilities, not legal advice. Organizations should consult their legal, HR, privacy, and security teams before configuring monitoring policies. Requirements vary by jurisdiction, industry, and employment contract.
Questions about data handling?
We are happy to walk through storage, retention, and access-control configuration with your security or privacy team.