Apps by reach
See every AI tool on your devices.
endlayer Monitoring is the AI monitoring layer of the endlayer control plane for AI. One row per AI app, coding agent, MCP server and skill across every enrolled device: who has it, what it reaches, whether it runs on its own, and what it costs.
Agents by reach
Token cost · 30 days
the Monitoring overview · example devices, not live data
An app list is not enough.
An app list tells you what people opened. Not which tools work on their own, which hold a key to an outside system, or whether anyone ever decided about them.
Installed is not the same as governed.
An app list says what people opened. Not which tools act on their own, which hold a key to an outside system, or whether anyone decided.
- Agents run in modes nobody approved
- MCP servers carry credentials off the device
- Undecided tools pile up with no owner
It answers from the device, and grades honestly.
A small unprivileged agent reports what AI is installed. Surfaces finds it, Monitoring counts it, Governance grades it against your rule.
- The device reports. Your policy decides
- Unknown is never counted as a pass
- Every publish is a version you can export
Nothing was looking where the AI runs.
Governance tools document intent. Gateways see traffic. The AI that matters moved onto laptops: coding agents, local models, MCP servers.
- We are an AI governance company
- Customers could not say what AI ran on their machines
- So we built a control plane for the device
Every AI tool, counted across the fleet.
Monitoring reads reports your devices already send. The list is there the first time you open it.
The shadow AI has names
Every AI tool anyone installed, on one list. The ones nobody has ruled on sort to the top.
You know which ones act alone
Seventeen of the sixty-four run unattended. The list says on how many machines each already does.
You can see where data leaves
Every outside host your tools can reach, and how many machines hold a key for it.
The bill has names on it
Thirty days of token cost, per tool rather than one number on a bill.
Each device reports. Monitoring makes one list.
Nothing extra is installed. The agent already on each device sends a report every fifteen minutes, and Monitoring adds the reports up.
Claude Code, Cursor, Codex CLI, Copilot, Ollama and twelve more.
Claude, Cursor, VS Code, Codex, OpenCode, Gemini, project files.
Chrome, Edge, Brave, Arc, Firefox, Safari and four more. Domains only.
Some details say unknown rather than a guess.
The agent reads the disk
No special permissions. It reads apps, config files and settings, and never runs them.
~3 MB · 21 signals · read-onlyIt sends a short report
What is installed and how it is set up. Machines report at staggered times.
every 15 minutes · 96 reports a dayThe report becomes rows
One row per tool, MCP server and skill on that device, written to your own platform.
your platform · never oursYour policy grades it
Your policy gives each fact a standing: approved, not allowed, or undecided.
versioned · attributed · reversibleYou see one list
Rows add up: one per tool across the fleet, ranked by devices.
live · no reloadSee who runs which AI, what it reaches and what it costs.
Monitoring reads the snapshot Surfaces already took. Switch it on for three devices free and watch the first thirty days fill in.
Five views, one row per tool.
This is the console, laid out the way you will use it: a list on the left, a table on the right. One row per tool, counted across every machine. Pick a view to see what it lists.
The fleet at a glance
Six counts across the top, each linking into its table. Below them, the fleet mix, fleet posture and thirty days of token cost. Undecided is drawn grey on purpose: nobody has looked, and that must not read as safe or unsafe.
Device mix
Tool installs by sanction
Fleet posture
Money, once. Every money figure in the console runs the same query, so two pages cannot disagree about the bill.
Non-autonomous AI tools
Every AI application on a device that cannot act on its own, ranked by how many devices carry it. The second tab reads the directory instead of the disk: which AI products hold OAuth grants to tenant data. Neither sees what the other does, so the page shows both.
| Tool | Vendor | Kind | Reach | Sanction | Last seen |
|---|---|---|---|---|---|
| Cursor | Anysphere | IDE | 142 devices | sanctioned | 2 min ago |
| ChatGPT Desktop | OpenAI | desktop app | 105 devices | undecided | 4 min ago |
| Claude Desktop | Anthropic | desktop app | 78 devices | sanctioned | 1 min ago |
| Ollama | Ollama | local runtime | 31 devices | undecided | 9 min ago |
| Windsurf | Codeium | IDE | 13 devices | unsanctioned | 16 min ago |
Read, never executed. Tools come from installed applications, config files and running processes. Nothing here is inferred from network traffic.
Autonomous agents
The same inventory, filtered to tools that can act unattended. Their permission mode, hooks and MCP connections let them run without anyone approving each step. This is the list a security lead reads first.
| Agent | Vendor | Unattended | Reach | MCP | Sanction |
|---|---|---|---|---|---|
| Claude Code | Anthropic | 7 devices | 38 devices | 4 hosts | undecided |
| Codex CLI | OpenAI | 3 devices | 24 devices | 2 hosts | unsanctioned |
| OpenCode | SST | — | 11 devices | 1 host | undecided |
| Goose | Block | 2 devices | 5 devices | — | undecided |
| Aider | open source | — | 3 devices | — | sanctioned |
Configuration first. The autonomy flag and the permission mode are what this view grades on. Anything deeper your admins switch on stays in your platform.
Off-device MCP hosts
One row per host your AI tools are configured to reach, with how much of the fleet reaches it and how many machines hold a credential. Only servers that reach off-device: a network host is a path data can leave by, a local one is not.
| Host | Fleet reach | Credentialed | Transport | Permitted |
|---|---|---|---|---|
| api.github.com | 153 devices | 153 holding a credential | http | permitted |
| api.figma.com | 151 devices | 154 holding a credential | http | permitted |
| sentry.io | 146 devices | 146 holding a credential | http | not listed |
| mcp.internal-crm.example | 21 devices | 19 holding a credential | sse | not listed |
Declarations are read, never followed. The agent parses the files that declare these servers. It never connects to one, so nothing here comes from the server itself.
Skills
Packaged instruction sets that agents can run. They are the quietest way capability enters a company, because a skill file is not an install. One row each, with which agents can run it and where it is declared.
| Skill | Kind | Agents | Fleet reach | Declared in | Says it does |
|---|---|---|---|---|---|
| deploy-prod | command | Claude Code | 29 devices | 3 repositories | Ship the current branch to production |
| db-migrate | command | Claude Code, Codex | 18 devices | 1 repository | Run pending migrations |
| customer-lookup | skill | Cursor | 9 devices | user scope | Fetch a customer record by email |
| rotate-keys | skill | OpenCode | 3 devices | user scope | Rotate cloud credentials |
Read, never run. A skill is catalogued from its declaration. The agent never executes one to find out what it does.
Usage, Logs and Maps used to live here and moved to Observability. Controls merged into Governance. Every old path still resolves.
Reach, autonomy, data paths and cost.
The parts a software inventory does not have. Each is a column or a control in the console.
How much of the fleet has it
Every row carries a bar, sorted by devices. The bar is the number. There is no colour to decode.
Which tools can act on their own
Agents get their own view, with the permission mode read from each tool’s settings. And how many machines it already runs unattended on.
Where an agent can send your data
Every outside host a tool can reach, and how many machines hold a key. Local-only servers are left out rather than padding the number.
Approved, not allowed, or nobody has looked
Three states against your policy. Undecided gets its own grey. It is a to-do list, not a zero.
What was signed in to, next to what is installed
Connect Microsoft and Apps gains a tab of AI products that can reach company data. The disk and the directory each see what the other cannot.
Approve or block a tool where you found it
Click a row and publish the decision. It becomes a numbered policy version. Nothing is removed from a device until an admin approves it.
Thirty days of cost, and where it came from
Token counts from the devices, priced against a versioned table. Local models show as free. Token cost, not spend: it is arithmetic, not your invoice.
New things appear on their own
Devices report every fifteen minutes and the view is a live query. Nobody has to run a scan.
Every finding gets a clear state.
Most dashboards have two colours: good and bad. Monitoring keeps five, because a gap never looks like a pass.
The device meets the rule as you published it.
Warn is the softer verdict, where your policy chose one.
A machine went quiet, or a list is stale. Never counted as a pass.
The control is switched off, so the fleet has no position on it.
On neither list. The queue Monitoring exists to shrink.
A list in priority order
Tools nobody approved and rules that are failing, ranked by how much of the fleet each touches.
Decisions with a version number
Every decision becomes a policy version, with your name and the time on it.
Proof it actually changed
When a blocked app goes, the next device report shows it. The proof is the fleet, not a closed ticket.
Your data stays in your own platform.
Everything Monitoring collects is written to your own endlayer platform, and read only by the people your administrators allow. We build endlayer. We hold no account in your platform, so there is nothing on our side to see.
Monitoring connects Surfaces and Governance.
Three questions, answered in order. Surfaces measures. Monitoring counts. Governance decides.
Surfaces
One row per device. Finds the AI tools, agents, models and keys on each one.
Read about Surfaces →Monitoring
One row per tool across the fleet: who has it, what it reaches, whether it is approved, what it costs.
Governance
The rules every device is graded against, with a version on every decision.
Read about Governance →Common questions.
What is endlayer Monitoring?
It is the AI monitoring layer of the endlayer control plane for AI. It turns what the agent reports from each device into one row per AI tool, coding agent, MCP server or skill: who has it, whether it runs on its own, what it reaches, whether it is approved, and what it costs.
How is this different from Surfaces?
Same facts, different question. Surfaces answers what is on this machine. Monitoring answers what is out there across all of them. Surfaces when one device is in trouble; here when a tool is on forty.
Can it read what people type into AI tools?
Yes, if your administrators switch it on. Conversation titles and messages are separate switches, off by default, and turning either on needs a typed reason that is kept with the name of whoever turned it on. Everything collected lands in your own endlayer platform, read only by the people your administrators allow. We never see it.
What happens when I block a tool?
Your decision publishes as a new policy version. Devices with the tool start failing that rule, and a removal request appears for an admin. Nothing is deleted until a person approves it. “Not allowed” is softer: the tool fails the rule and stays installed.
Why does the MCP count leave out local servers?
Because the question is whether data can leave the device. A server with a network address is a way out; one that only runs on the laptop is not. Counting both would make the number bigger and less useful.
Why do you call it token cost instead of spend?
Spend is a figure on an invoice. This is token counts from your devices priced against a versioned table, so the page can say which table it used and name any model it had no price for.
Does it need a gateway, a proxy or a connector?
No. The device views need only the agent, and nothing changes on your network. Connecting Microsoft adds a directory tab to Apps, and only after you consent.
Take control of the AI already in your company.
It is already installed on the laptops. You can see all of it by this afternoon.