Monitoring changedcowork/monitoring
Nearest release: v2.1.291, published under an hour after upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 6 Oct 2026 03:05 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 6 Oct 2026 03:07 UTC.
Upstream edited
Recorded here
Lines+10added
Lines−4removed
From line
44
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits4to this page, all time
The whole hunk
from line 44, old and new numbered
/
from line 44
4444
4545| `otlpContentCapture` on the device | Content that events carry |
4646| - | - |
47| Not set, on a first-party deployment | User prompt text, model response text, and tool inputs |
47| Not set, on a first-party deployment | User prompt text, model response text, and the [`toolDetails` content](#security-and-privacy) |
4848| Not set, on a [third-party deployment](/docs/third-party/claude-desktop/overview) | No content. Events carry metadata only |
4949| Set to a list of [categories](/docs/third-party/claude-desktop/telemetry#content-capture) | The content in the listed categories. Listing `userPrompts` also includes model response text |
5050| Set to an empty list, `[]` | No content. Events carry metadata only |
5151
52Metadata includes `workspace.host_paths` and, on first-party deployments, `user.email`. The key doesn't control either one. See [Security and privacy](#security-and-privacy).
53
5254### Event correlation
5355
5456When a user submits a prompt, Cowork may make multiple API calls and run several tools. The `prompt.id` attribute links all events back to the single prompt that triggered them.
from line 75
7375| `user.account_id` | Account ID in tagged format matching Anthropic admin APIs (for example, `user_01BWBeN28...`) |
7476| `user.id` | Anonymous device/installation identifier |
7577| `user.email` | User email |
76| `workspace.host_paths` | Host workspace directories selected in the desktop app (string array) |
78| `workspace.host_paths` | Paths of the folders the user connected to the task (string array) |
7779| `terminal.type` | Terminal type (`non-interactive` for Cowork) |
7880
7981<Note>
from line 246
244246## Security and privacy
245247
246248* Events are only exported when an admin configures the OTLP endpoint
247* Which content events carry is set per device by the [`otlpContentCapture`](#content-capture) key: `userPrompts` for user prompt text, `assistantResponses` for model response text, and `toolDetails` for the `tool_input` attribute (file paths, URLs, search patterns, and other arguments)
249* The [`otlpContentCapture`](#content-capture) key on each device sets which content events carry. Each category you list in the key adds its content. The [full category list](/docs/third-party/claude-desktop/telemetry#content-capture) has two more than these three:
250 * `userPrompts`: user prompt text
251 * `assistantResponses`: model response text
252 * `toolDetails`: the arguments a tool was called with, in `tool_input` and `tool_parameters`, such as shell commands, file paths, URLs, and search patterns. It also covers the text of a failed tool's error message, in `error` on the [tool result event](#tool-result-event)
248253* On Claude Desktop version 1.17377 or later, events that carry user prompt text also carry model response text, even when the key doesn't list `assistantResponses`
249* On Claude Desktop version 1.17377 or later, when `otlpContentCapture` isn't set on a device in a first-party deployment, events carry user prompt text, model response text, and tool inputs. To export metadata only, set the key to an empty list, `[]`
254* On Claude Desktop version 1.17377 or later, when `otlpContentCapture` isn't set on a device in a first-party deployment, events carry user prompt text, model response text, and the `toolDetails` content. To export metadata only, set the key to an empty list, `[]`
255* Metadata includes `workspace.host_paths`, the paths of the folders a user connects to a task. `otlpContentCapture` doesn't control this attribute, so events carry the paths even when the key is `[]`. If folder names can be sensitive, configure your telemetry backend to filter or redact it
250256* On first-party deployments, `user.email` is always included in event attributes, so configure your telemetry backend to filter or redact it if this is a concern
251257* On third-party deployments, `user.email` is absent; the export identifies users with the `enduser.id` resource attribute, controlled by the [`endUserAttribution`](/docs/third-party/claude-desktop/configuration#enduserattribution) setting
252258
No line in this hunk matches that.