Decide your tracing posture before production: leave it on while debugging, then disable it or route spans to your own backend for sensitive workloads. The env var is the simplest global kill switch; the RunConfig flag covers single sensitive runs. Do not assume traces are local, they are exported unless you turn them off.

Context: The official Agents SDK tracing docs confirm the tracing default. Tracing is enabled by default, collecting LLM generations, tool calls, handoffs, guardrails, and custom events into traces viewable on the Traces dashboard. It can be disabled globally with the OPENAI_AGENTS_DISABLE_TRACING env var, in code with set_tracing_disabled, or per run with RunConfig tracing_disabled. Tracing is unavailable for organizations under a Zero Data Retention policy.