# Log Masking

**Log Masking lets Admins and Workspace Admins hide a workflow step's input and output values in execution logs.** Sensitive data such as PII, credentials, and financial records is no longer casually visible to workspace members browsing logs — while the workflow keeps running exactly as before.

* **Mask from the builder** — right-click any step and select **Mask log data**. The step's input and output are masked for everyone in the workspace.
* **Reveal on demand** — Admins and Workspace Admins can unmask a value in the logs when they genuinely need it, and every reveal is recorded in the audit log.
* **Manage in one place** — a central **Data masking** view in Workspace settings shows every masked step, who masked it, and when.

Masking affects only how log data is displayed; it does not change how your workflow executes. Only Admins and Workspace Admins can mask, unmask, or reveal step data.

> **Info:** If you're interested in using Log Masking, please reach out to your Customer Success Manager or Account Executive to request access.

[Read more in the docs](https://tray.ai/documentation/platform/enterprise-core/security-compliance/log-masking)
