Executive AI Monitoring
Fleet-wide oversight. Superuser credentials required.
Organization token is required

Overview

Updated just now
Department risk heat mapRISK / 100
Scan volume · 7 daysPEAK
Regulatory exposureTRIGGERS
Highest-risk devicesPEAK / 100

Risk distribution

VIEW ALL →
TOTAL 0

7-day org-wide trend

Top regulations triggered

Top LLM endpoints

Most active devices

VIEW ALL →

Recent critical events

VIEW ALL →

Devices

Updated just now
DeviceUser · DepartmentOSCriticalLast seenScansPeakBlocked

macOS-leo

leo@acme.com · Sales
← DEVICES  /  MACOS-LEO

macOS-leo

HIGH EXPOSURE dev-035 · leo@acme.com · macOS 14.2 · last seen 4d ago
Total scans
611
on this device
Peak risk
79
/ 100
Critical
8
events
Blocked
8
PII denied
Redacted
82
PII stripped
Findings
183
PII instances

Risk distribution

TOTAL 0

Top LLM endpoints

Activity heatmap

Less More
MONDAY · 11:00–12:00
11scans
Blocked1
Redacted2
Warned2
Logged6
Top processSafari
Top domainapi.openai.com
Peak risk72 / 100
Pinned. Click the cell again to unpin.

Scan log

· —
TimeDomainProcessLLMFindingsRiskAction

Departments

Updated just now
PII exposure breakdown by team

Engineering detail

Scans
5,400
Critical
131
Blocked
117
Devices
18
Devices in this department

Scan Log

Updated just now
Time ↓UserDeptDomainLLMRiskActionRegulations

Monitoring

Updated just now
Outbound traffic, alert rules and notification settings
Monitoring Toggle
Network monitoring is active · 44 agents reporting
Events (24h)
44
outbound connections
Volume out
67.9 MB
across all agents
Categories
5
of 5 classified
Flagged
5
need review

Traffic by category

LLM API14
Telemetry12
Unknown SaaS8
Dev Tools7
File Upload3

Severity breakdown

CRITICAL3
WARN3
INFO38

Flagged events

5 OPEN
walter@acme.com → wetransfer.com2d ago
FILE UPLOAD · 12.1 MB · dev-019
elena@acme.com → wetransfer.com3d ago
FILE UPLOAD · 21.9 MB · dev-028
zoe@acme.com → cdn.synthhub.io3d ago
UNKNOWN SAAS · 296.1 KB · dev-046

Category legend

LLM API
Known LLM provider endpoints (OpenAI, Anthropic, Google)
File Upload
Multipart uploads to external hosts
Unknown SaaS
Unclassified third-party services
Telemetry
Analytics, crash reporting, update checks

Outbound traffic

TimeUserDeviceDomainCategorySeverityBytes out
2d agozoe@acme.comdev-046github.comDEV TOOLSINFO308.7 KB
2d agowendy@acme.comdev-020sentry.ioTELEMETRYINFO282.0 KB
2d agotrent@acme.comdev-017telemetry.vscode.devTELEMETRYINFO379.8 KB
2d agocarol@acme.comdev-003registry.npmjs.orgDEV TOOLSINFO262.8 KB
2d agoyara@acme.comdev-022api.openai.comLLM APIINFO198.7 KB
2d agoerin@acme.comdev-005generativelanguage.googleapis.comLLM APIINFO174.0 KB
2d agopriya@acme.comdev-039api.anthropic.comLLM APIINFO71.4 KB
2d agovictor@acme.comdev-018generativelanguage.googleapis.comLLM APIINFO114.5 KB
2d agocarol@acme.comdev-003pypi.orgDEV TOOLSINFO378.4 KB
2d agojudy@acme.comdev-010sentry.ioTELEMETRYINFO168.1 KB
2d agouma@acme.comdev-044pypi.orgDEV TOOLSINFO62.6 KB
2d agotrent@acme.comdev-017segment.ioTELEMETRYINFO226.2 KB
2d agosara@acme.comdev-042app.datalake.runUNKNOWN SAASINFO252.2 KB
2d agobob@acme.comdev-002sentry.ioTELEMETRYINFO197.8 KB

Alert rules

Critical block spikeCRITICAL×
risk_score ≥ 90
→ ciso@acme.com · cooldown 30m · Any scan scoring 90 or above triggers immediately
Large outbound uploadHIGH×
bytes_out > 25000000
→ security@acme.com · cooldown 1h · File-upload category exceeding 25 MB
Stale device check-inMEDIUM×
last_seen > 72h
→ ciso@acme.com · cooldown 24h · Agent has not reported within three days
New rule
Name
Severity
Field
Op
Value
Notify email
Cooldown
Description

Triggered alerts

TimeRuleDeviceSeverityStatus
2d agoCritical block spikedev-007CRITICALOPEN
2d agoLarge outbound uploaddev-019HIGHOPEN

Email notifications (SMTP)

SMTP host
Port
Username
Password
From address

Security Report

Updated just now
Weekly summary · Apr 11–17, 2026

Executive Security Summary

Weekly summary · Apr 11–17, 2026 · Acme Corporation · 47 devices
ELEVATED
ORG RISK POSTURE

Key findings

Recommendations

Department risk breakdown

Server Settings

Updated just now
Organization-level configuration

Organization

Organization name
Org token
Distribute this to agents via their config
Agent retention

Global policies

Block CRITICAL everywhere
Override agent enforcement
Require minimum k-anonymity
k ≥ 5 org-wide
Weekly email digest
To ciso@acme.com

API endpoints

Ingest URL
Webhook (optional)
Fire on CRITICAL events

Superusers

ciso@acme.com
Admin · you
OWNER
security@acme.com
Admin · added Mar 12
compliance@acme.com
Viewer · added Jan 15

Danger zone

Purge scan history
Delete all org scans older than retention
Rotate org token
Invalidates all agent connections