Information safe to share with support
Good diagnostics identify the failing layer without exposing the data that protects the site.
Include
- POM AI version and WordPress site URL;
- multisite subsite URL or blog context;
- feature, MCP method, resource URI, prompt name, or tool name;
- UTC or local time with timezone;
- public error code, HTTP status, and message;
- whether the request was read, dry run, write, estimate, or execution;
- relevant object IDs, not full private content;
- input counts, prompt length, file type and size, not the sensitive input itself;
- expected result and current observed state;
- redacted browser or MCP client name and version;
- steps already tried.
Never include
- full license keys;
- MCP API keys, bearer or refresh tokens, authorization codes, or signatures;
- passwords, application passwords, cookies, or nonces;
- customer, order, payment, health, or credential data;
- private source images, audio, prompts, or unpublished content unless an approved channel explicitly requires them;
- raw database rows, configuration files, or complete request headers.
POM AI’s MCP audit log redacts recognized sensitive keys and truncates long strings, but redaction is best-effort. Review every exported diagnostic manually.
If a credential appears in a screenshot or log, rotate or revoke it before continuing the support conversation.
Related guides: MCP audit privacy, privacy, and users and credentials boundary.