pilot
Live activity events per day in range Open Live →
Top open alerts critical & high, newest first Triage →
Sanctioned tools on the allowlist CSV
Unapproved tools not on the allowlist Security →
Attribution health live 1h / 24h / 7d pct_ok — Epic A gate ≥95% on trailing 7d; service principals count as OK
Identity coverage attributed vs unattributed usage — a rate nobody alerts on is how we assert fleet coverage we do not have
By tool unattributed first
By host top 50 by unattributed events
Repositories pseudonymous repo refs — which codebases AI tools touch CSV
Providers volumes by AI provider CSV
Events by provider
Daily events by provider
OTel instrumented apps model + token + cost depth lives on Apps — proxy metering above cannot see tokens
OTel instrumented apps model + token depth lives on Apps — proxy metering above cannot see tokens
Provider API metering by source class per-provider volume, bytes, and status mix CSV
New sources calling an LLM API first-ever provider-API call inside the window — the shadow-AI-in-software signal
Daily events by provider and source class
Instrumented applications per-service LLM usage — click a service for its model inventory and trend CSV
Model distribution which models OTel sources call — tokens and estimated cost (metadata only, no prompt content) CSV
Instrumented applications per-service LLM usage — click a service for its model inventory and trend CSV
Model distribution which models OTel sources call, with token totals — metadata only, no prompt content
Per-team usage click a team for identity, members, models, and rename; unresolved identities bucket into (unattributed) CSV
Model usage by team tokens and estimated cost per model — employee tooling path (OTel apps have no team dimension; see Apps) CSV
Team × tool matrix tokens per team and tool — hover a cell for events and est. cost
Cost by team
Tools in use click a row for the drill-down — sanctioned status, first/last seen, version when known CSV
Repositories click a repo for the drill-down; repos with guardrail flag hits are highlighted CSV
Fleet enforce coverage install-path (policy loaded) + honor rate under mode=enforce — zero blocks is not clean when posture is dark
Detail
Match flags by detector click a row for evidence + triage View all open findings → CSV
Matches by severity where the risk sits across every triggered detector
Flag hits per day
Detection volume guardrail matches per day — total + top detectors
Enforce blocks blocked / would-block / override per day
Unapproved tool discovery everything not on the sanctioned list (Claude Code, Cursor, Kilo Code) — click a row for detail CSV
MCP server usage mcp_call tool invocations by server (schema v1.1 tool_use events) — correlate with unapproved-MCP findings
Secret break-glass (overrides) endpoint resubmit overrides of secret-pattern blocks — pilot audit trail; metadata only CSV
Save this filter set to come back to it
streaming
Activity trail
| Time | Score | User | Tool | Model | Event | Tokens | Est. cost | Flags / factors |
|---|
Attribution health live 1h / 24h / 7d pct_ok — Epic A gate ≥95% on trailing 7d
Collector coverage share of enrolled devices actually reporting — the gap is the part that is not green
Coverage over time healthy % of enrolled devices and gap count per day
Fleet enforce coverage install path + honor rate + fail-open — who can enforce today without SQL
Who can enforce today
Fail-open inventory (no bundle / shadow / stale)
Honor rate by rule blocked ÷ (blocked + would_block)
Enrolled devices devices needing attention first; revoked devices are excluded; ≤100 per page
User usage ordered by tokens · ≤100 per page · click a pseudonym for the per-user timeline CSV
JIT provisioning first-login failures & SLA
Surfaces identity.jit_provision_failed and identity.jit_sla_breach from the audit trail. Runbook: docs/security/jit-provisioning-sla.md