OBSERVABILITY PLATFORM · Profile revision 1

Langfuse

An OpenTelemetry-rooted observability platform with typed generation, agent, tool, retriever, evaluator, and guardrail observations plus export and privacy controls.

observabilityopentelemetryprivacyexport

Why it is in the map

Langfuse contributes a typed observation model and concrete masking, retention, deletion, API, and self-hosting evidence.

Tracevity boundary

A documented field can support reconstruction, but its presence alone does not prove completeness, authenticity, authorization, or external settlement.

Profile findings

What the documentation can—and cannot—establish

Each row distinguishes source evidence from Tracevity's bounded interpretation. “Not documented” describes the reviewed sources; it does not prove an implementation cannot record the artifact.

01

System identity

Documented

Trace, session, observation hierarchy, user, and release metadata support execution correlation.

Tracevity interpretation

This does not guarantee a stable agent-instance or agent-definition version across arbitrary integrations.

Limit

Canonical agent instance and definition/version fields are not mandatory for every observation.

Primary evidence (1)
02

Principal and delegation

Partially documented

User attribution is representable, but authenticated principal and delegation semantics are not standardized.

Tracevity interpretation

A user ID and agent nesting must not be presented as authentication or an authority chain.

Limit

Delegated identity, credential type/scope/expiry, and elevation are not canonical fields.

Primary evidence (1)
03

Instruction and context

Documented

Instruction and retrieval context can be recorded in typed or generic observation payloads.

Tracevity interpretation

Recorded payloads do not prove that all selected context or source versions survived.

Limit

Context fingerprint, source authenticity, and explicit missing-context representation are not universal.

Primary evidence (1)
04

Decision artifacts

Partially documented

Evaluator and guardrail outputs are representable as recorded decision evidence.

Tracevity interpretation

They do not expose hidden reasoning or guarantee a plan, selected alternative, or policy rationale.

Limit

Plan, decision summary, selected alternative, calibrated confidence, and refusal reason are not universal typed fields.

Primary evidence (1)
05

Model activity

Documented

Core model request/response, identity, usage, cost, and latency evidence is representable.

Tracevity interpretation

Actual coverage and exact provider model version depend on instrumentation.

Limit

Provider-specific version, cache, error, and content completeness are not guaranteed for every integration.

Primary evidence (1)
06

Tool and MCP activity

Documented

Tool identity, arguments/results, error, latency, and trace hierarchy can be represented.

Tracevity interpretation

A tool observation is execution telemetry, not proof of authority or downstream settlement.

Limit

MCP server identity, credential context, retry, and downstream provider correlation are not universal.

Primary evidence (1)
07

Effects

Not documented

Some read/action semantics exist, but a first-class external-effect settlement model does not.

Tracevity interpretation

Successful tool output cannot establish external state change.

Limit

Requested effect, acceptance, transaction settlement, external effect state, and state delta are not canonical.

Primary evidence (1)
08

Human control

Partially documented

Human review artifacts can be retained.

Tracevity interpretation

Review or annotation is not necessarily pre-action authorization or intervention.

Limit

Approval, rejection, edit, interruption, takeover, rollback request, identity, and authority are not universal.

Primary evidence (1)
09

Outcome

Partially documented

Reported success/failure and evaluation evidence can be reconstructed from retained observations.

Tracevity interpretation

Observation outcome does not independently verify destination state.

Limit

External verification, partial/ambiguous settlement, rollback, and compensation are not canonical outcomes.

Primary evidence (1)
10

Trace integrity

Not documented

Langfuse records have lifecycle controls but no documented universal integrity guarantee.

Tracevity interpretation

Trace IDs and timestamps support correlation, not independent verifiability.

Limit

Clock provenance, immutability, append-only behavior, signature, tamper evidence, and independent verification are absent.

Primary evidence (1)
11

Portability

Documented

OTel foundations and native API/export surfaces provide multiple portability paths.

Tracevity interpretation

Typed vendor observation meaning may not survive every destination or conversion.

Limit

Complete schema versioning, import coverage, documented conversion, and exact semantic loss remain unknown.

Primary evidence (1)
12

Privacy

Documented

Sensitive prompt, output, tool, PII, code, and metadata capture can be reduced through documented controls.

Tracevity interpretation

Control availability does not prove that an integration enabled masking or minimized every sensitive field.

Limit

Coverage, hashing, screenshots, deployment-specific retention, and customer capture defaults remain implementation dependent.

Primary evidence (1)

Reconstruction reading

Do not collapse these findings into one score.

This profile describes documented evidence surfaces. Whether they are sufficient depends on the reconstruction question and the other identity, authorization, tool, and destination records available.

Potentially useful evidence

  • Identity: Trace, session, observation hierarchy, user, and release metadata support execution correlation.
  • Principal: User attribution is representable, but authenticated principal and delegation semantics are not standardized.
  • Context: Instruction and retrieval context can be recorded in typed or generic observation payloads.
  • Decisions: Evaluator and guardrail outputs are representable as recorded decision evidence.
  • Models: Core model request/response, identity, usage, cost, and latency evidence is representable.

Explicit gaps or uncertainty

  • Effects: Requested effect, acceptance, transaction settlement, external effect state, and state delta are not canonical.
  • Integrity: Clock provenance, immutability, append-only behavior, signature, tamper evidence, and independent verification are absent.

Source register

8 reviewed primary sources

  1. Observability data modelLangfuse · OFFICIAL DOCUMENTATION · observed August 28, 2026 · current
    Open source ↗
  2. Observation typesLangfuse · OFFICIAL DOCUMENTATION · observed August 28, 2026 · current
    Open source ↗
  3. Observations APILangfuse · OFFICIAL DOCUMENTATION · observed August 28, 2026 · current
    Open source ↗
  4. API and Data PlatformLangfuse · OFFICIAL DOCUMENTATION · observed August 28, 2026 · current
    Open source ↗
  5. MaskingLangfuse · OFFICIAL DOCUMENTATION · observed August 28, 2026 · current
    Open source ↗
  6. Data deletionLangfuse · OFFICIAL POLICY · observed August 28, 2026 · current
    Open source ↗
  7. Privacy FAQLangfuse · OFFICIAL POLICY · observed August 28, 2026 · current
    Open source ↗
  8. Agent graphsLangfuse · OFFICIAL DOCUMENTATION · observed August 28, 2026 · current
    Open source ↗

Next question

What evidence does your use case require?

Move from documented field presence to an explicit reconstruction target, or examine selected directional format mappings without changing this system's documentation posture.

Trace Reconstruction Requirements Explore compatibility evidence