Give every request a stable identity

Accept a well-formed upstream request identifier or generate one at the application boundary. Include it in structured logs, outbound requests, queued jobs, and the public error response. This lets support connect a user-visible failure to internal evidence without showing stack traces.

Use consistent field names and UTC timestamps. Free-form log sentences are hard to search and easy to leak values into.

Log decisions, not entire payloads

Record the route, actor class, result, duration, dependency status, and stable error code. Redact authorization headers, cookies, passwords, tokens, payment data, and sensitive form fields before they reach the logger.

Sampling can control normal traffic volume, but errors and unusually slow operations often need separate retention and alert policies.

  • Use allowlisted log fields.
  • Separate security audit events from diagnostic logs.
  • Cap field length and nesting.
  • Test the redaction layer with representative secrets.

Keep display errors off in production

The response should provide a safe message and request identifier. Detailed exceptions belong in access-controlled logging and error tracking. Configure startup and fatal errors at the runtime level because application handlers may not run.

A diagnostic endpoint should report dependency health without revealing versions, credentials, internal hostnames, or full configuration.

Verification checkpoint

Trigger a controlled exception and confirm the browser receives no path, query, stack, credential, or software-version detail while the internal record remains actionable by request ID.