AI Monitoring usage dashboard

pilot

Live activity events per day in range Open Live →

Top open alerts critical & high, newest first Triage →

Sanctioned tools on the allowlist CSV

Unapproved tools not on the allowlist Security →

Attribution health live 1h / 24h / 7d pct_ok — Epic A gate ≥95% on trailing 7d; service principals count as OK

Identity coverage attributed vs unattributed usage — a rate nobody alerts on is how we assert fleet coverage we do not have

By tool unattributed first

By host top 50 by unattributed events

Repositories pseudonymous repo refs — which codebases AI tools touch CSV

Providers volumes by AI provider CSV

Events by provider

Daily events by provider

Instrumented applications per-service LLM usage — click a service for its model inventory and trend CSV

Model distribution which models OTel sources call — tokens and estimated cost (metadata only, no prompt content) CSV

Instrumented applications per-service LLM usage — click a service for its model inventory and trend CSV

Model distribution which models OTel sources call, with token totals — metadata only, no prompt content

Per-team usage click a team for identity, members, models, and rename; unresolved identities bucket into (unattributed) CSV

Model usage by team tokens and estimated cost per model — employee tooling path (OTel apps have no team dimension; see Apps) CSV

Team × tool matrix tokens per team and tool — hover a cell for events and est. cost

Cost by team

Tools in use click a row for the drill-down — sanctioned status, first/last seen, version when known CSV

Models CSV

Versions observed

Daily usage

Repositories click a repo for the drill-down; repos with guardrail flag hits are highlighted CSV

Match flags by detector click a row for evidence + triage CSV

Matches by severity where the risk sits across every triggered detector

Flag hits per day

Detection volume guardrail matches per day — total + top detectors

Enforce blocks blocked / would-block / override per day

Unapproved tool discovery everything not on the sanctioned list (Claude Code, Cursor, Kilo Code) — click a row for detail CSV

MCP server usage mcp_call tool invocations by server (schema v1.1 tool_use events) — correlate with unapproved-MCP findings

Secret break-glass (overrides) endpoint resubmit overrides of secret-pattern blocks — pilot audit trail; metadata only CSV

Break-glass grants manager approval, expiry, revoke · metadata only CSV Audit pack

streaming

Activity trail

Live activity trail with security score, user, tool, tokens, cost and flags
Time Score User Tool Model Event Tokens Est. cost Flags / factors

Attribution health live 1h / 24h / 7d pct_ok — Epic A gate ≥95% on trailing 7d

Collector coverage share of enrolled devices actually reporting — the gap is the part that is not green

Coverage over time healthy % of enrolled devices and gap count per day

Fleet enforce coverage install path + honor rate + fail-open — who can enforce today without SQL

Who can enforce today

Fail-open inventory (no bundle / shadow / stale)

Honor rate by rule blocked ÷ (blocked + would_block)

Enrolled devices devices needing attention first; revoked devices are excluded; ≤100 per page

User usage ordered by tokens · ≤100 per page · click a pseudonym for the per-user timeline CSV

JIT provisioning first-login failures & SLA

Surfaces identity.jit_provision_failed and identity.jit_sla_breach from the audit trail. Runbook: docs/security/jit-provisioning-sla.md

Recent failures

SLA breaches

Audit events latest 200 matching the filters