Data retention and permissions
Data retention
Choose which Agent Monitor data MintMCP stores and how long it keeps it under Enterprise settings > Settings > Retention. These settings apply to the whole organization. Metadata is always kept because dashboards and reports depend on it, full content is your choice, and content you turn off is never written in the first place rather than stored and hidden.
Where this data comes from
| Surface | What MintMCP stores | Controlled by | Kept for |
|---|---|---|---|
| Agent Monitor (Claude Code, Codex, Copilot, Cursor hooks) | Bounded previews of user prompts, agent responses, and tool inputs/outputs that the agent's hooks send | Agent conversations, Tool calls toggles | Logs period |
| MCP gateway | Tool name, status, timing, and argument/result previews for every call that passes through the gateway | Tool calls toggle | Logs period |
| Claude Inference Hooks (opt-in) | The latest model input Claude sends for evaluation, with detected secrets redacted and long input truncated, plus the evaluation result | Agent conversations toggle (the model input); the evaluation result is metadata and always kept | Logs period |
| LLM gateway (opt-in) | A usage summary (model, tokens, cost, latency, policy outcome) plus a short prompt preview and tool result previews | Agent conversations toggle (prompt preview), Tool calls toggle (tool result previews) | Logs period |
| Reports | Daily aggregated usage stats: requests, tool calls, tokens, and cost by user | Not configurable; no content to toggle | Reports period |
| Exports (OTLP, Splunk HEC, SIEM export to your own storage) | The same data stored above, in export format | Same toggles as the source data | Your own system's retention once exported |
What's never stored
- The raw hook payload your coding agent sends. Only the bounded preview described above reaches MintMCP.
- Full LLM gateway request and response bodies. Only the usage summary and short prompt preview are kept.
- The model call itself, when neither the LLM gateway nor Claude Inference Hooks is in use. It goes directly from your agent to the model provider, so MintMCP never sees it.
What gets stored
Metadata is always stored because dashboards and reports depend on it, while full content can be turned off:
| Data | What it includes | Default | Configurable |
|---|---|---|---|
| Agent conversations - full | All system prompts, user messages, and agent responses | On | Yes |
| Agent conversations - metadata | Message timestamps, user identity, agent identity, and input/output token counts | Always on | No (required) |
| Tool calls - content | Tool name plus arguments and results | On | Yes |
| Tool calls - metadata | Tool name, status, and timing | Always on | No (required) |
Turning off Tool calls - content stops storing tool arguments and results, so they also stop appearing in exports. Only the tool-call metadata is kept.
How long it's kept
| Setting | Covers | Options | Default |
|---|---|---|---|
| Logs | All logged data configured above | 7, 30, or 90 days | 30 days |
| Reports | Reports generated from logs | 7, 30, or 90 days | 30 days |
Each record is stamped with its own expiry when it's written, using whatever period was in effect at that time, so changing the period later doesn't shorten or extend data that's already stored. Expired data stops appearing in the UI and in queries as soon as its retention period ends, and MintMCP permanently deletes it shortly after.
What these settings don't cover
- Once data leaves MintMCP through an export, it follows your own system's retention, not MintMCP's. Expiring a record on our side doesn't reach a copy that's already landed in your SIEM, bucket, or log pipeline.
- Tool-call approval requests store a preview of the tool arguments so approvers can review the call. The preview stops appearing once the Logs period ends, and it isn't affected by the Tool calls - content toggle. See Require approval for a tool call.
- Turning on Mint Guard sends MCP tool call content to Google Cloud's Model Armor, in your organization's deployment region (US or EU), for scanning. Mint Guard is off by default.
Changing retention
- Go to Enterprise settings and open the Settings tab.
- Expand Retention.
- Toggle a content setting, or pick a new period for Logs or Reports.
- Confirm the change in the dialog.
Changes reach runtime within about a minute and apply to new data only. Data that's already stored keeps its original settings, so contact MintMCP support if you need existing conversation or tool-call content deleted, or existing data kept longer.
Retention controls are available on the Enterprise plan. Changing them requires the Admin role or a custom role with the Enterprise settings permission; see Roles and permissions.
Permissions
| Role | View all logs | View own logs | Edit rules |
|---|---|---|---|
| Admin | ✅ | ✅ | ✅ |
| Member | ❌ | ✅ | ❌ |
Custom roles can grant org-wide log access or Guardrail management without full admin, for example View org-wide logs for a security team. See Roles and permissions for the full permission set.
FAQ
Does turning off a content toggle delete what's already stored? No. The toggle only changes what's written going forward. Contact MintMCP support if you need existing content removed early.
Do my exports respect these settings? Yes. Exports are built from the data MintMCP stores, so content you've turned off is never exported. Once a record is exported, it follows your own system's retention; see What these settings don't cover.
Where is my data stored? Your organization runs in either the US or the EU deployment, and MintMCP stores your data in that region.
What's in "Reports"? Aggregated usage stats, requests, tool calls, tokens, and cost by user, with no prompt or tool-call content.
How do I get data deleted earlier than its retention period? Contact MintMCP support.