Discover
no integrationKnow what is actually running.
read from files on the disk, never executed
- Apps, coding agents, MCP servers and local models
- Accounts and API keys, including the key in a dotfile
- Found without an integration to install first
Every AI tool, agent, and model call across your company: surfaced, monitored, and governed from one plane.
no card, no call · one laptop reporting in a minute
One agent on the device feeds all three. There is no connector to build, no proxy in the path and no gateway to route through. Everything is read from files already on the disk.
An unprivileged agent on every machine finds the AI apps, coding agents, MCP servers, local models, browser AI usage, accounts and exposed credentials, without being told they exist.
Which apps and agents are active, what they can reach through MCP, whose account they run on, which projects and repositories they see, what they cost, and which machines have gone quiet.
Every signal is graded against your immutable policy version. Unsanctioned tools, unattended agents, personal accounts and credential-bearing MCP servers are flagged, owned and tracked to closed, with the record kept.
Every tool arrived the same way: one person, one laptop, one Tuesday. Nothing was recorded, so nothing can be seen, attributed or proved.
.env files git is not ignoring.No proxy in the path, no gateway to route through and no connector per tool. Everything is read from files already on the disk.
Including whether a coding agent may act unattended. All 21 →
A tool installed at 9:00 is in the inventory by 9:15.
mac, Windows, Linux, iOS, Android, servers and cloud.
No proxy to route through, no gateway to stand up.
guardrails act on every device today; cloud connectors and SDK ingestion are planned, and the same rules apply to them the day they ship
Six layers, and each one is useful on its own. Together they turn AI nobody catalogued into something you can see, price, stop and prove. One agent on the device feeds all six.
Know what is actually running.
read from files on the disk, never executed
Turn every report into one record.
macOS, Windows, Linux, servers and cloud
See what each one can reach.
declared, never dialled
Know what it costs before the invoice.
by tool, person and project
Act at the moment it happens.
inside the agent, on the device
Grade it, and keep the proof.
every publish is a version
21 signals every fifteen minutes · Surface, Monitor and Govern are the three pages behind the six layers
21 signals every fifteen minutes · every signal, listed →
Six surfaces, one agent, and nothing installed in the path. Pick a surface to see what is read off the disk.
They write and run code on the machine, sometimes without being watched.
The permission mode nobody reviewed, the MCP servers it can reach, and which repositories are in its scope. None of it crosses a gateway.
The agent's own configuration, in the user's home directory.
The chat window that never goes through your network.
Which account it is signed in on. Corporate work runs through somebody's personal ChatGPT and Claude login, over TLS to a domain you already allow.
Installed applications, and the account each one is signed in as.
The connectors that hand an agent your credentials.
They are declared in a client's config file and carry tokens off the device, and no CASB has a connector for them.
The client config files that declare them. Declared, never dialled.
A model running on the laptop. No invoice, no log, no gateway.
It runs entirely on the device, so nothing you bill against will ever show that it existed. And nothing in the path can see it.
The runner on disk, the models it has pulled, and the port it listens on.
The extension and the side panel that read the page you are on.
Extensions install per browser profile, ask for permission once, and are never inventoried again.
Extension manifests, per profile, and what each one declares it can see.
A provider key in a file git is not ignoring.
Keys sit in project .env files and in shell profiles. One of them is one push away from public.
Presence and location only. The value is discarded before evidence is built.
the eighteenth tool needs a signature, not an integration
How you start depends on how big you are. What you get does not.
no minimum number of people · no charge per tool connected · nothing in the path of your traffic
Nothing about your devices leaves your network.
What AI ran on one machine, and what it cost. Not the platform.
$ endlayer enrollenrolment code 4F2K-9QX1waiting for an organisation to accept…accepted · credential stored 0600 · org set by the approver$ endlayer doctorconfig /etc/endlayer/endlayer.tomlignored nonedelivery reachable · next scan in 847s$ first snapshot delivered21 signals · 3 pass · 2 warn · 3 fail · 13 info
that was one laptop · the same thing runs on five thousand
no card · delivery off until you turn it on · never elevates
Yes, for PII leaking into a prompt, and for tools being used in ways nobody authorised. It is not on by default, and turning it on records who enabled it and the reason why. Your admin can narrow what is collected at any time, and the agent cannot widen it.
No. Nothing changes on your network. Everything is read from files already on the disk, which is also why desktop apps, coding agents and local models show up at all. none of them go through a gateway.
No. It runs as the person using the machine and reads only what that account can already read. It never elevates, and it never executes any of the AI tools it finds.
Seventeen are recognised by name. Anything else still surfaces as an unidentified AI process with the account and the machine attached, and naming it properly takes a signature, not an integration, so there is no per-tool work for you either way.
Within fifteen minutes. Every device sends a snapshot every fifteen minutes, so a tool installed at 9:00 is in the inventory by 9:15.
Both. Every signal is measured against your policy version, and what fails gets an owner, a state and a date it closed. Real-time guardrails inside the agent act on the device as it happens: prompts are scored before they run, and secrets and personal data are warned on, redacted or blocked on the way out. Removing an installed app is the one action that waits for a person: an administrator approves the request before anything is uninstalled. Every action is recorded.
It is already installed on the laptops. You can see all of it by this afternoon.