Skip to main content

AI Insights

AI Insights connects an overview of agent activity to the recorded events behind it. The app opens in light mode; the header theme button switches every page, chart, and account dialog to dark mode and saves your preference.

Read the report, then investigate

The report overview contains a headline, risk score, expandable analysis, and report history. Three tabs separate Explore activity, Findings, and Recommendations. Counts and charts come from recorded events. A live AI analysis adds interpretations and recommendations with cited evidence.

Use Run AI analysis to choose a period and provider. Configure an organization provider in Settings or use the platform provider when available. Curated Northwind reports are explicitly labeled fictional demo and authored narrative; they do not require a model call.

Interactive charts

ViewWhat to look forClick-through
Decision trendsCompare daily volume with block rate; a busy day is not necessarily a risky day.Select a bar or area point to inspect that UTC day. The expandable daily table provides the same access.
Decision mixAllowed, approval-required, audited, and blocked shares. Hover details appear below the donut.Select a segment or decision row.
Agents and MCP serversCompare blocks, audits, and block rates across hosts or servers.Select an entity to see its matching events.
Weekday/hour heatmapRecurring blocked activity, including scheduled builds outside working hours.Select a cell to inspect that weekday and hour across the chosen period.
Rules and behavior categoriesThe rules and taxonomy nodes behind interventions. An event can belong to multiple categories.Select a rule or category.
SourcesActivity from coding hooks, MCP hooks, and automation.Select a source to investigate its events.

The evidence drawer keeps the selected time range and filters, shows the matching total, and paginates results. Expand an event to inspect its command or tool arguments. Open in audit log carries those filters into the full log. Narrative timeline links open the exact cited event.

Decisions and dates

Audited means recorded without intervention. An audit-only event can preserve an original BLOCK or REQUIRE_APPROVAL decision; that does not mean the action was actually blocked or approved. The evidence view exposes the recorded outcome and original decision.

Live 7d, 30d, and 90d buttons use the current time. A stored report retains its original period. Curated Northwind reports open with Demo period, keeping the report, charts, and evidence aligned to the same date range. Select a live period to return to current activity.

Charts and investigation time filters use UTC. Date-only audit end dates include the full UTC day; timestamp ranges preserve their precise endpoints. If the summary reaches its 20,000-event sample limit, the page warns that it may be incomplete.

See Explore the demo to try these workflows with sample data.