Explore the demo
Explore AI Agent Lens with Northwind Robotics, a fictional workspace containing 90 days of activity across seven agents. Use it to investigate security findings, follow evidence, and try policy settings. No signup or AI key is needed.
Open the demo
- On the front page, choose Explore demo, or open the demo directly.
- Click the Demo credentials · click to sign in card. It signs you in automatically; you do not need to enter its details on the regular sign-in page.
- AI Insights opens in your own temporary workspace. Changes you make affect only your copy.
Start with AI Insights
The report highlights three stopped credential-theft attempts and a CI policy gap. Expand Read the full analysis for the explanation, then use the three tabs to investigate:
| Tab | What you can do |
|---|---|
| Explore activity | Compare daily volume, block rates, decisions, agents, MCP servers, and recurring time patterns. Select a chart or row to inspect its matching events. |
| Findings | Open a finding to review what happened, its supporting evidence, and the recommended response. Expand Incident timelines to follow a sequence of actions. |
| Recommendations | Review suggested changes and the evidence behind them. Suggestions are available for review; they are not automatically applied. |
Keep Demo period selected to explore the same date range as the report. The 7d, 30d, and 90d buttons show activity relative to the current time. Chart filters use UTC; the Audit Log displays event times in your local timezone.
Follow a finding to its evidence
- In Findings, open A poisoned README led to three credential-theft attempts.
- Review the supporting events: a README fetch, three blocked credential attempts, and an allowed test command.
- Expand Incident timelines and select an event number. The Audit Log opens with that exact event selected.
You can also start from a chart. Select a decision, day, agent, server, rule, or heatmap cell to open the evidence drawer. Expand an event for details, browse additional results, or choose Open in audit log to continue with the same filters.
Find a policy gap
In Explore activity, select Agents, switch the ranking to Audits, and open ci-runner-07. Its installer activity includes AUDIT events with an original BLOCK decision. Audit-only mode recorded those actions without stopping them.
Compare this with the production-change finding for ci-runner-12. REQUIRE_APPROVAL means a human decision was requested; it does not establish that approval was granted. Elena's read-only database activity provides an example of routine allowed work.
Explore the workspace
Use Overview for a summary, Agents for host activity, and Audit Log to search and filter individual actions. Compliance, Posture, and OWASP Matrix let you explore how the recorded activity relates to controls and coverage.
In Settings, try changing the organization name or enforcement mode. A policy change updates your temporary workspace's settings; it does not rewrite historical event decisions. The demo does not connect to your agents or infrastructure.
Reset or leave the demo
Select Reset demo in the top banner to discard your changes and open a fresh workspace. Sign out ends your demo session. Sessions expire after one hour of inactivity and can also end during a service update; reopen the demo to start again. If the demo is temporarily full, the entry page will ask you to retry.
About the sample data
The report is an authored fictional scenario, and all its evidence is synthetic. Charts are calculated from those event records. Fresh sessions use recent dates, so you can explore a complete activity history whenever you visit.
The demo has no live AI analysis, AI credentials, account-security changes, invitations, or access-token creation. To use your own agents and run analysis with a configured AI provider, create an account or sign in to your workspace.
See the AI Insights guide for more detail on reports, charts, decisions, and date filters.