What Sam receives
- Call timings and duration.
- Input and output sizes and token counts.
- Shape statistics, such as punctuation proportions.
- A one-way fingerprint for comparing patterns.
- Call, feature and release identifiers, and outcome status.
Sam watches how your AI behaves without receiving the prompts, replies or conversation context inside its calls. Your ideas, your customers’ words and your application’s content stay in your application.
See the two-call integrationYou should be able to understand whether your AI is doing its job without handing over the work it does. Prompts can hold your intellectual property. Conversations can hold someone else’s private information.
We built Sam around a different question: what can the behaviour of a call tell us? How long did it take? Did it repeat? Was the input unexpectedly large? Did a source stop reporting?
Those signals let Sam notice meaningful changes. When they aren’t enough, Sam should say so. Asking you to trust Sam starts with limiting what Sam receives.
Measurements are computed locally, in your application. Only the measurements and the fingerprint reach the Sam platform, where they are stored.
Today, the fingerprint is a one-way hash your code computes. It shows Sam when calls repeat, not what they are about. Coming with the inspector SDK: a fingerprint that generalises the content, so Sam can see when a prompt’s length or meaning changes without seeing the facts in it. Only categories from a shared, public codebook will leave your application, never the underlying embedding, so the original text can’t be recovered from it.
Sam does need the purpose you choose to describe: “This digest should run once each night.” That description helps Sam propose checks for you to confirm.
Sam does not receive the prompt context inside your AI calls: the conversation, retrieved documents or model input. Knowing the job is different from reading the work.
The codebook’s granularity sets how much detail a fingerprint can carry. The finer a category, the more it says about a call, so the codebook is deliberately coarser on sensitive subjects. A fingerprint can show that a call is about health, for example, but not which condition.
We audit the codebook so that no category is sensitive in itself.
Some patterns only show up across many teams: workloads on the same model getting worse on the same day, for example. Sam looks for them in anonymised measurements and fingerprints, so every customer benefits from what Sam learns.
No customer can identify another, or see another’s features, data or findings. The codebook behind every fingerprint is trained on public data only, never on customer content.
Sam runs on the Sam platform, on resources separate from the workloads being watched, so watching never slows them down. Notifications leave through the channels you explicitly connect. Running Sam inside your own environment isn’t available yet.
Today, halting is a switch you control, and every change to it is recorded. Coming: authority per action and environment, approvals that expire, and no way for Sam to approve its own requests.
In the inspector SDK, nothing is sent from someone else’s device until that person agrees. The SDK is coming; until then, consent is yours to collect.
Numbers, findings and stop decisions come from code. Sam’s model, when it arrives, will help phrase explanations and draft checks, never decide them. You can inspect the evidence and the limits behind a finding.
Useful attention, a deliberate content boundary and authority that stays with you.
See how Sam helps