1. Map logging points. Include clients, servers, proxies, error tracking, tools and temporary files. Inventory what each retains and who can read it. Debug logging can expose the same document processed before the model call.
2. Separate content from metadata. Start with request identifier, status, duration, model and consumption. Avoid bodies, authorization headers and personal values. Review error messages too: validation failures should not echo the complete input.
3. Test with recognizable fictional markers. Run successful, invalid and interrupted calls. Search logs under your control for those markers, including exports and monitoring. Fix the component capturing them and repeat the affected scenario.
4. Set retention and access rules. Document metadata retention and the purpose of content auditing. Encryption does not remove the need for access control or deletion. During troubleshooting, authorize necessary inspection without turning temporary debugging into permanent collection.