Skip to content
the 21 signals

Twenty-one things, read off every device.

Every fifteen minutes, one unprivileged agent reads these from files already on the disk. No tool is executed, no traffic is inspected, and nothing in the list needs a connector.

21
signals on every device
Including whether a coding agent may act unattended.
15min
between snapshots
A tool installed at 9:00 is in the inventory by 9:15.
7
platforms, one agent
mac, Windows, Linux, iOS, Android, servers and cloud.
0
changes to your network
No proxy to route through, no gateway to stand up.
what it reads

Every signal, and the one line it reads.

Seven groups. The first five are what an AI governance tool has to know; the last two are what a security team already asks about the same machine. Nothing here needed a connector, a survey, or a list to look for.

All 21 signals, in the order the agent reads them.

  1. 01Tools & agents

    Tools and agents

    Which AI tools, CLIs and coding agents are installed

    ai_tooling
  2. 02Tools & agents

    Autonomy

    Whether an agent can act on its own, and how far it is pre-approved

    ai_autonomy
  3. 03Apps & web

    AI web usage

    Visits to known AI domains, by category and count

    ai_web_usage
  4. 04Apps & web

    Installed software

    The wider application inventory on the device

    installed_software
  5. 05MCP & access

    MCP servers

    Declared servers, their transport, host and capability

    mcp_servers
  6. 06MCP & access

    Credentials

    That a provider key exists, its variable name, and whether git ignores it

    ai_credentials
  7. 07Accounts & spend

    Accounts

    Corporate, personal or unknown, with the organisation and email domain

    ai_accounts
  8. 08Accounts & spend

    Usage and spend

    Token and usage records the tools already wrote locally

    ai_usage
  9. 09Projects & data

    Projects and data

    Repositories as owner/name, with a bounded data-file inventory

    ai_projects
  10. 10The device

    Device facts

    Make, model, OS and version

    device_facts
  11. 11The device

    Fleet enrolment

    Whether the device is enrolled in management

    mdm_enrollment
  12. 12The device

    Automatic updates

    Whether OS updates install without being asked

    auto_updates
  13. 13The device

    Patch level

    How far behind the operating system is

    os_patch_level
  14. 14Security posture

    Disk encryption

    Whether the volume is encrypted

    disk_encryption
  15. 15Security posture

    Screen lock

    Whether the screen locks, and after how long

    screen_lock
  16. 16Security posture

    Firewall

    Whether the host firewall is on

    firewall
  17. 17Security posture

    Endpoint protection

    Whether an EDR agent is present

    edr_present
  18. 18Security posture

    Network posture

    The device's network configuration

    network_posture
  19. 19Security posture

    Browser policy

    Whether browser policy is in force. Verified, never modified

    browser_policy
  20. 20Security posture

    Password policy

    Whether a password policy is enforced

    password_policy
  21. 21Security posture

    Admin accounts

    Which accounts on the device hold administrator rights

    admin_accounts
read them for yourself

Every one of these, from a machine of yours, in sixty seconds.

Three devices free, no card. Then compare the list above with what actually came back.

how a scan runs

Sixty seconds on the machine. Nothing in the path.

Every tier of agent follows the same bounded, outbound-only path. One failed check never stops a scan — that check reports unknown and every other result still completes.

schedule

Checks on your cadence, jittered so a fleet never arrives in one wave.

collect

Reads approved signals without launching or executing the AI it finds.

reason locally

Applies the active tier’s capability on the machine or in your environment.

snapshot

Produces versioned, redacted evidence — facts and decisions with provenance.

spool · sink

Lands on disk first, then leaves through one encrypted outbound route.

built-in boundaries

What it will not read.

The list above is the whole list. These limits live in the collector, not in an admin setting, and sensitive values are removed on the endpoint before anything is stored.

We do not read secrets

Credential presence is reported. The value is discarded on the device, before evidence is built.

We do not read source code

Repository context is enough. File contents stay untouched.

We do not collect conversations by default

Prompts, responses and transcripts stay off until an administrator switches them on, and the record says who did, and why.

We do not inspect traffic

No proxy, packet capture, payload inspection or gateway.

We do not run discovered tools

The agent observes. It never launches what it finds.

We do not track people

No precise location, raw device identity or personal account IDs.

administrator control · narrow collection only · the collector refuses requests outside these boundaries

what comes back

Six clear result states.

Every signal is graded against the policy version in force, and the verdict keeps the rule that made it. Colour, symbol and word — never colour alone.

✓ pass

Measured and meets policy.

✕ fail

Measured and breaks policy.

! warn

Allowed, but needs attention.

· info

A fact with no judgement.

— unknown

The device could not measure it.

○ not applicable

The control does not exist here.

Missing evidence stays unknown and a missing policy stays ungraded — never a pass. How grading works, end to end, is on the platform page.

start with endlayer

Take control of the AI already in your company.

It is already installed on the laptops. You can see all of it by this afternoon.

activity4h slices
30d ago22d15d7dnow