Skip to main content
Privacy for Teams

Governance without hidden surveillance

AI TokenScope governs company-funded AI access and spending. It should not be configured as a hidden employee-surveillance system.

Our approach

TokenScope is a governance tool for managing company-funded AI access. Used responsibly, it gives organizations visibility into spending and policy compliance without crossing into surveillance of individual work output.

Disclose monitoring to employees

Organizations should inform employees that AI usage is monitored for governance purposes before enabling TokenScope.

Collect only what is needed

Configure the minimum data collection required for your governance goals. Metadata-only mode is available when prompt content review is not needed.

Restrict prompt access by role

Not every administrator needs to see prompt text. Role-based access controls limit who can view prompt content.

Prefer aggregated views

Team and project dashboards surface patterns without requiring review of individual prompts.

Configure retention appropriately

Shorter retention periods reduce exposure. Retention is configurable per workspace.

Start in Observe mode

Begin with full visibility and no enforcement. Introduce policies gradually after reviewing usage patterns.

Prompt visibility by role

The table below shows what each role can see by default. Items marked “Configurable” depend on workspace settings. Items marked “Own only” are visible only for the user's own activity.

RoleTotal costRequest countProject attributionPrompt categoryPolicy resultFull prompt textIndividual identity
DeveloperOwn onlyOwn onlyOwn onlyOwn onlyOwn onlyOwn onlyOwn only
Team managerYesYesYesYesYesConfigurableYes
Workspace administratorYesYesYesYesYesYesYes
Finance userYesYesYesNoNoNoYes
Security reviewerNoYesYesYesYesConfigurableYes
AuditorYesYesYesYesYesNoYes
Yes — visible by defaultOwn only — own activity onlyConfigurable — depends on workspace settingsNo — not visible to this role

Prompt storage modes

Administrators choose how prompt content is stored. The choice affects classification capability, audit search, and employee privacy exposure.

Full content

Request metadata and prompt text are stored per the configured retention period.

Prompt text stored: Yes
Metadata stored: Yes
Cryptographic hash: No

Default mode. Enables audit-trail search and classification review.

Metadata only (Privacy Mode)

Team plan or above

Prompt text is never stored. A cryptographic hash is recorded for audit continuity.

Prompt text stored: No
Metadata stored: Yes
Cryptographic hash: Yes

Configurable per workspace in Settings. Recommended for workloads involving sensitive information where prompt review is not required.

Retention

Retention periods control how long usage data is kept. Shorter retention reduces data exposure. Longer retention supports compliance and historical reporting.

Free

30 days

default

Startup

90 days

default

Team

1 year

default

Business

2 years

default

Data deletion on request. Customers can request deletion of their workspace data at any time by emailing hello@aitokenscope.com.

Configurable retention. Business and Enterprise plans support custom retention periods shorter than the default.

See the Privacy Policy for the complete data handling and deletion terms.

Auditability

Administrator actions and access to sensitive data are recorded in the audit trail.

Prompt content access

When an administrator views an individual prompt, the access is recorded with the administrator's identity and timestamp.

Available

Administrative actions

Policy changes, user provisioning, role changes, and workspace configuration changes are logged.

Available

Audit record export

Audit logs are exportable for compliance reporting or external review. Available on Startup plan and above.

Available

Audit log retention

Audit logs follow the same retention schedule as usage data and are subject to the same deletion policy.

Available

Implementation checklist

Before deploying TokenScope to a team, work through the following with your legal, HR, and IT stakeholders.

  • Inform employees that AI usage through company accounts is monitored for governance purposes.
  • Define and document your organization's acceptable-use policy for company-funded AI.
  • Select a storage mode — full content for audit search, metadata-only for lower prompt exposure.
  • Restrict prompt-text access to roles that have a legitimate governance need.
  • Configure a retention period appropriate for your compliance and reporting requirements.
  • Start in Observe mode. Review usage patterns before introducing enforcement policies.
  • Establish a process for reviewing disputed classification decisions.
  • Reassess storage, retention, and enforcement policies periodically as the team grows.

Not legal advice

This page describes product capabilities, not legal advice. Organizations should consult their legal, HR, privacy, and security teams before configuring monitoring policies. Requirements vary by jurisdiction, industry, and employment contract.

Questions about data handling?

We are happy to walk through storage, retention, and access-control configuration with your security or privacy team.