Twenty-one things, read off every device.
Every fifteen minutes, one unprivileged agent reads these from files already on the disk. No tool is executed, no traffic is inspected, and nothing in the list needs a connector.
Every signal, and the one line it reads.
Seven groups. The first five are what an AI governance tool has to know; the last two are what a security team already asks about the same machine. Nothing here needed a connector, a survey, or a list to look for.
All 21 signals, in the order the agent reads them.
- 01Tools & agents
Tools and agents
Which AI tools, CLIs and coding agents are installed
ai_tooling - 02Tools & agents
Autonomy
Whether an agent can act on its own, and how far it is pre-approved
ai_autonomy - 03Apps & web
AI web usage
Visits to known AI domains, by category and count
ai_web_usage - 04Apps & web
Installed software
The wider application inventory on the device
installed_software - 05MCP & access
MCP servers
Declared servers, their transport, host and capability
mcp_servers - 06MCP & access
Credentials
That a provider key exists, its variable name, and whether git ignores it
ai_credentials - 07Accounts & spend
Accounts
Corporate, personal or unknown, with the organisation and email domain
ai_accounts - 08Accounts & spend
Usage and spend
Token and usage records the tools already wrote locally
ai_usage - 09Projects & data
Projects and data
Repositories as owner/name, with a bounded data-file inventory
ai_projects - 10The device
Device facts
Make, model, OS and version
device_facts - 11The device
Fleet enrolment
Whether the device is enrolled in management
mdm_enrollment - 12The device
Automatic updates
Whether OS updates install without being asked
auto_updates - 13The device
Patch level
How far behind the operating system is
os_patch_level - 14Security posture
Disk encryption
Whether the volume is encrypted
disk_encryption - 15Security posture
Screen lock
Whether the screen locks, and after how long
screen_lock - 16Security posture
Firewall
Whether the host firewall is on
firewall - 17Security posture
Endpoint protection
Whether an EDR agent is present
edr_present - 18Security posture
Network posture
The device's network configuration
network_posture - 19Security posture
Browser policy
Whether browser policy is in force. Verified, never modified
browser_policy - 20Security posture
Password policy
Whether a password policy is enforced
password_policy - 21Security posture
Admin accounts
Which accounts on the device hold administrator rights
admin_accounts
Every one of these, from a machine of yours, in sixty seconds.
Three devices free, no card. Then compare the list above with what actually came back.
Sixty seconds on the machine. Nothing in the path.
Every tier of agent follows the same bounded, outbound-only path. One failed check never stops a scan — that check reports unknown and every other result still completes.
schedule
Checks on your cadence, jittered so a fleet never arrives in one wave.
collect
Reads approved signals without launching or executing the AI it finds.
reason locally
Applies the active tier’s capability on the machine or in your environment.
snapshot
Produces versioned, redacted evidence — facts and decisions with provenance.
spool · sink
Lands on disk first, then leaves through one encrypted outbound route.
What it will not read.
The list above is the whole list. These limits live in the collector, not in an admin setting, and sensitive values are removed on the endpoint before anything is stored.
We do not read secrets
Credential presence is reported. The value is discarded on the device, before evidence is built.
We do not read source code
Repository context is enough. File contents stay untouched.
We do not collect conversations by default
Prompts, responses and transcripts stay off until an administrator switches them on, and the record says who did, and why.
We do not inspect traffic
No proxy, packet capture, payload inspection or gateway.
We do not run discovered tools
The agent observes. It never launches what it finds.
We do not track people
No precise location, raw device identity or personal account IDs.
administrator control · narrow collection only · the collector refuses requests outside these boundaries
Six clear result states.
Every signal is graded against the policy version in force, and the verdict keeps the rule that made it. Colour, symbol and word — never colour alone.
Measured and meets policy.
Measured and breaks policy.
Allowed, but needs attention.
A fact with no judgement.
The device could not measure it.
The control does not exist here.
Missing evidence stays unknown and a missing policy stays ungraded — never a pass. How grading works, end to end, is on the platform page.
Take control of the AI already in your company.
It is already installed on the laptops. You can see all of it by this afternoon.