Application-LLM traffic (AIM-103): company software vs employee tools calling LLM provider APIs, metered at the proxy. application = server/DC/CI source; employee = endpoint source; unknown = not yet classified (subnet inventory pending). Metadata only — volume, bytes, status; no tokens, models, or content.
Provider API metering by source class per-provider volume, bytes, and status mixCSV
New sources calling an LLM API first-ever provider-API call inside the window — the shadow-AI-in-software signal
Daily events by provider and source class
Application LLM telemetry (AIM-105): APM-class per-service signals from OTel GenAI instrumentation — model inventory, token metering, errors and latency. Metadata only; there is deliberately no employee/user dimension here. Complements the App-LLM view (proxy metering) with in-app instrumentation.
Instrumented applications per-service LLM usage — click a service for its model inventory and trendCSV
Per-team usage click a team for identity, members, and rename; unresolved identities bucket into (unattributed)CSV
Team × tool matrix tokens per team and tool — hover a cell for events and est. cost
Cost by team
Tools in use click a row for the drill-down — sanctioned status, first/last seen, version when knownCSV
Repositories are pseudonymized by design (HMAC repo refs — data minimization). Live data shows those refs, not raw Git remotes. Human-readable labels (security group only) are the explicit de-pseudonymization path and every access is audited. Do not treat truncated mono hashes as a bug.
Repositories click a repo for the drill-down; repos with guardrail flag hits are highlightedCSV
Guardrail match flags (observe-only, v1) and unapproved tool discovery. Aggregates only — matched content is never stored; user identities withheld here by policy. Click a row for detector evidence and triage links.
Detail
Match flags by detector click a row for evidence + triageCSV
Flag hits per day
Unapproved tool discovery everything not on the sanctioned list (Claude Code, Cursor, Kilo Code) — click a row for detailCSV
MCP server usage mcp_call tool invocations by server (schema v1.1 tool_use events) — correlate with unapproved-MCP findings
Live event trail — per-event security score (1–10) and estimated cost. Restricted to analyst + admin. Pseudonymous; matched content is never stored.
streaming
Activity trail
Time
Score
User
Tool
Model
Event
Tokens
Est. cost
Flags / factors
Collector fleet — enrolled devices and heartbeat health. Restricted to the security group; access is logged. A device is healthy within one heartbeat interval, stale within three, dead beyond that, never seen before its first heartbeat. Enrolled-but-silent hosts appear as coverage gaps within one heartbeat interval (AIM-452) — they do not vanish.
Collector coverage share of enrolled devices actually reporting — the gap is the part that is not green
Enrolled devices devices needing attention first; revoked devices are excluded
User-level view — restricted to the security group. Access is logged (audit trail). Pseudonymous identifiers only; identity reveal is role-gated in identity-sync.
User usage (top 500 by tokens) click a pseudonym for the per-user timelineCSV
Audit trail — immutable record of sign-ins, authorization decisions and sensitive actions. Restricted to auditors and security admins.