Skip to content
the monitoring layer

See every AI tool on your devices.

endlayer Monitoring is the AI monitoring layer of the endlayer control plane for AI. One row per AI app, coding agent, MCP server and skill across every enrolled device: who has it, what it reaches, whether it runs on its own, and what it costs.

Get startedBook a demoSee the views ↓every enrolled device · every 15 minutes · updates as reports arrive
endlayer|MonitoringOverview
Apps
64
distinct tools
Agents
17
act unattended
MCP servers
23
off-device hosts
Unsanctioned
11
installs against policy

Apps by reach

Cursor142
ChatGPT Desktop105
Claude Desktop78
All apps

Agents by reach

Claude Code38
Codex CLI24
OpenCode11
All agents

Token cost · 30 days

$4,212priced from table v7
Claude Code$1,840
Cursor$1,120
Codex CLI$690
Usage

the Monitoring overview · example devices, not live data

endlayer, in three
Surfaces finds what is on each machine.
Monitoring counts it across the fleet.you are here
Governance decides what is allowed.
why

An app list is not enough.

An app list tells you what people opened. Not which tools work on their own, which hold a key to an outside system, or whether anyone ever decided about them.

why you need Monitoring

Installed is not the same as governed.

An app list says what people opened. Not which tools act on their own, which hold a key to an outside system, or whether anyone decided.

  • Agents run in modes nobody approved
  • MCP servers carry credentials off the device
  • Undecided tools pile up with no owner
why the endlayer platform

It answers from the device, and grades honestly.

A small unprivileged agent reports what AI is installed. Surfaces finds it, Monitoring counts it, Governance grades it against your rule.

  • The device reports. Your policy decides
  • Unknown is never counted as a pass
  • Every publish is a version you can export
why we built it

Nothing was looking where the AI runs.

Governance tools document intent. Gateways see traffic. The AI that matters moved onto laptops: coding agents, local models, MCP servers.

  • We are an AI governance company
  • Customers could not say what AI ran on their machines
  • So we built a control plane for the device
Your AI gatewaySees traffic that goes through it. A coding agent calling a vendor API from a laptop never does.nothing on the device
Your CASBHas connectors for SaaS apps. Nobody makes one for an MCP server written into a file on a laptop.no MCP connector exists
Your device management toolKnows Cursor is installed. Not whether it can act unattended, or what it reaches.autonomy is not in an app list
Your directoryKnows what people signed in to. Not what is installed, or what runs without signing in.local models never sign in
what you get

Every AI tool, counted across the fleet.

Monitoring reads reports your devices already send. The list is there the first time you open it.

01

The shadow AI has names

Every AI tool anyone installed, on one list. The ones nobody has ruled on sort to the top.

Apps → undecided → sanction drawer
02

You know which ones act alone

Seventeen of the sixty-four run unattended. The list says on how many machines each already does.

Agents → unattended → Governance · modes
03

You can see where data leaves

Every outside host your tools can reach, and how many machines hold a key for it.

MCP servers → credentialed → permit or block
04

The bill has names on it

Thirty days of token cost, per tool rather than one number on a bill.

Overview → token cost → Usage
how it works

Each device reports. Monitoring makes one list.

Nothing extra is installed. The agent already on each device sends a report every fifteen minutes, and Monitoring adds the reports up.

17AI tools known by name

Claude Code, Cursor, Codex CLI, Copilot, Ollama and twelve more.

7places MCP is declared

Claude, Cursor, VS Code, Codex, OpenCode, Gemini, project files.

10browsers

Chrome, Edge, Brave, Arc, Firefox, Safari and four more. Domains only.

0things run by us

Some details say unknown rather than a guess.

Three devices report into your platform, your policy grades each row, and one list across the fleet forms.laptops and desktopsmac · windows · linuxphones and tabletsiOS · androidcloudVMs · containersevery device, every 15 minutesreportreportreportyour platformnever oursCursorapprovedClaude Codeapprovedmcp: api.figma.comundecidedOllamaapprovedChatGPT, personal accountnot allowedpolicy v7one list, across the fleetCursor142Claude Code38Ollama31ChatGPT10564 tools · ranked by devices · live
01

The agent reads the disk

No special permissions. It reads apps, config files and settings, and never runs them.

~3 MB · 21 signals · read-only
02

It sends a short report

What is installed and how it is set up. Machines report at staggered times.

every 15 minutes · 96 reports a day
03

The report becomes rows

One row per tool, MCP server and skill on that device, written to your own platform.

your platform · never ours
04

Your policy grades it

Your policy gives each fact a standing: approved, not allowed, or undecided.

versioned · attributed · reversible
05

You see one list

Rows add up: one per tool across the fleet, ranked by devices.

live · no reload
start with monitoring

See who runs which AI, what it reaches and what it costs.

Monitoring reads the snapshot Surfaces already took. Switch it on for three devices free and watch the first thirty days fill in.

see it working

Five views, one row per tool.

This is the console, laid out the way you will use it: a list on the left, a table on the right. One row per tool, counted across every machine. Pick a view to see what it lists.

Monitoring · Overview

The fleet at a glance

Six counts across the top, each linking into its table. Below them, the fleet mix, fleet posture and thirty days of token cost. Undecided is drawn grey on purpose: nobody has looked, and that must not read as safe or unsafe.

Device mix

apps 64agents 17MCP 23skills 41

Tool installs by sanction

sanctionedundecidedunsanctioned

Fleet posture

passwarnfailunknown

Money, once. Every money figure in the console runs the same query, so two pages cannot disagree about the bill.

Monitoring · Apps

Non-autonomous AI tools

Every AI application on a device that cannot act on its own, ranked by how many devices carry it. The second tab reads the directory instead of the disk: which AI products hold OAuth grants to tenant data. Neither sees what the other does, so the page shows both.

On devicesWith data access
ToolVendorKindReachSanctionLast seen
CursorAnysphereIDE142 devicessanctioned2 min ago
ChatGPT DesktopOpenAIdesktop app105 devicesundecided4 min ago
Claude DesktopAnthropicdesktop app78 devicessanctioned1 min ago
OllamaOllamalocal runtime31 devicesundecided9 min ago
WindsurfCodeiumIDE13 devicesunsanctioned16 min ago

Read, never executed. Tools come from installed applications, config files and running processes. Nothing here is inferred from network traffic.

Monitoring · Agents

Autonomous agents

The same inventory, filtered to tools that can act unattended. Their permission mode, hooks and MCP connections let them run without anyone approving each step. This is the list a security lead reads first.

AgentVendorUnattendedReachMCPSanction
Claude CodeAnthropic7 devices38 devices4 hostsundecided
Codex CLIOpenAI3 devices24 devices2 hostsunsanctioned
OpenCodeSST11 devices1 hostundecided
GooseBlock2 devices5 devicesundecided
Aideropen source3 devicessanctioned

Configuration first. The autonomy flag and the permission mode are what this view grades on. Anything deeper your admins switch on stays in your platform.

Monitoring · MCP servers

Off-device MCP hosts

One row per host your AI tools are configured to reach, with how much of the fleet reaches it and how many machines hold a credential. Only servers that reach off-device: a network host is a path data can leave by, a local one is not.

HostFleet reachCredentialedTransportPermitted
api.github.com153 devices153 holding a credentialhttppermitted
api.figma.com151 devices154 holding a credentialhttppermitted
sentry.io146 devices146 holding a credentialhttpnot listed
mcp.internal-crm.example21 devices19 holding a credentialssenot listed

Declarations are read, never followed. The agent parses the files that declare these servers. It never connects to one, so nothing here comes from the server itself.

Monitoring · Skills

Skills

Packaged instruction sets that agents can run. They are the quietest way capability enters a company, because a skill file is not an install. One row each, with which agents can run it and where it is declared.

SkillKindAgentsFleet reachDeclared inSays it does
deploy-prodcommandClaude Code29 devices3 repositoriesShip the current branch to production
db-migratecommandClaude Code, Codex18 devices1 repositoryRun pending migrations
customer-lookupskillCursor9 devicesuser scopeFetch a customer record by email
rotate-keysskillOpenCode3 devicesuser scopeRotate cloud credentials

Read, never run. A skill is catalogued from its declaration. The agent never executes one to find out what it does.

Usage, Logs and Maps used to live here and moved to Observability. Controls merged into Governance. Every old path still resolves.

every feature

Reach, autonomy, data paths and cost.

The parts a software inventory does not have. Each is a column or a control in the console.

Cursor142
ChatGPT Desktop105
Claude Code38
reach

How much of the fleet has it

Every row carries a bar, sorted by devices. The bar is the number. There is no colour to decode.

Claude Code · 38 devices7 unattended
can act with nobody watching
autonomy

Which tools can act on their own

Agents get their own view, with the permission mode read from each tool’s settings. And how many machines it already runs unattended on.

data paths

Where an agent can send your data

Every outside host a tool can reach, and how many machines hold a key. Local-only servers are left out rather than padding the number.

approved 37undecided 16not allowed 11
64 tools16 waiting on a decision
standing

Approved, not allowed, or nobody has looked

Three states against your policy. Undecided gets its own grey. It is a to-do list, not a zero.

cross-check

What was signed in to, next to what is installed

Connect Microsoft and Apps gains a tab of AI products that can reach company data. The disk and the directory each see what the other cannot.

Codex CLI · 24 devicespolicy v14 → v15
approvedundecidednot allowedblocked
published to the disallowed list · attributed to you
decide from the row

Approve or block a tool where you found it

Click a row and publish the decision. It becomes a numbered policy version. Nothing is removed from a device until an admin approves it.

$4,212last 30 days
priced from table v72 models ran locally · free
token cost

Thirty days of cost, and where it came from

Token counts from the devices, priced against a versioned table. Local models show as free. Token cost, not spend: it is arithmetic, not your invoice.

live

New things appear on their own

Devices report every fifteen minutes and the view is a live query. Nobody has to run a scan.

what it tells you

Every finding gets a clear state.

Most dashboards have two colours: good and bad. Monitoring keeps five, because a gap never looks like a pass.

pass
Checked, and fine.

The device meets the rule as you published it.

fail · warn
Checked, and not fine.

Warn is the softer verdict, where your policy chose one.

unknown
We could not check.

A machine went quiet, or a list is stale. Never counted as a pass.

ungraded
No rule for it yet.

The control is switched off, so the fleet has no position on it.

undecided
Nobody has looked.

On neither list. The queue Monitoring exists to shrink.

you get

A list in priority order

Tools nobody approved and rules that are failing, ranked by how much of the fleet each touches.

you get

Decisions with a version number

Every decision becomes a policy version, with your name and the time on it.

you get

Proof it actually changed

When a blocked app goes, the next device report shows it. The proof is the fleet, not a closed ticket.

where your data lives

Your data stays in your own platform.

Everything Monitoring collects is written to your own endlayer platform, and read only by the people your administrators allow. We build endlayer. We hold no account in your platform, so there is nothing on our side to see.

Collected from the devices you enrol
Toolsid, name, vendor, detection source, last seen
Agentswhether it can act alone, its permission mode, and where it already does
MCP servershost, transport, environment variable names, credential-bearing flag
Skillsname, kind, which agents can run it, where it is declared
Accountssigned-in AI accounts, plan, organisation
Token usehow many tokens per model, priced against a versioned table
Prompts and conversationsconversation titles and messages, two separate switches, both off by default
Read-only, alwaysthe agent parses what is on the disk; no tool, model or MCP server is ever started to learn about it
Who can see it and who cannot
Stored inyour own endlayer platform, from the first report onward
Read bythe people your administrators allow, and only those — access is granted and revoked by your admins, not by us
Not uswe build and ship endlayer; we hold no account in your platform and cannot open, query or export what it holds
Content switchesturning on titles or messages takes an administrator and a typed reason, recorded with their name and the time
Ownershipthe data is yours and stays under your administrators’ control — if the platform changes hands, it goes with it
how it connects to Surfaces and Governance

Monitoring connects Surfaces and Governance.

Three questions, answered in order. Surfaces measures. Monitoring counts. Governance decides.

01 · surfaces

Surfaces

What is on this machine?

One row per device. Finds the AI tools, agents, models and keys on each one.

Read about Surfaces →
02 · monitoring

Monitoring

What is out there, across all of them?

One row per tool across the fleet: who has it, what it reaches, whether it is approved, what it costs.

03 · governance

Governance

What should be allowed?

The rules every device is graded against, with a version on every decision.

Read about Governance →
One machineSurfaces finds Codex CLI on a laptop.
The fleetMonitoring shows it on 24 devices, undecided.
A decisionGovernance publishes v14: Codex CLI disallowed.
The regrade24 devices fail on their next report. Events lists them.
The proofHistory has v14, who and when. The pack cites it.
common questions

Common questions.

What is endlayer Monitoring?

It is the AI monitoring layer of the endlayer control plane for AI. It turns what the agent reports from each device into one row per AI tool, coding agent, MCP server or skill: who has it, whether it runs on its own, what it reaches, whether it is approved, and what it costs.

How is this different from Surfaces?

Same facts, different question. Surfaces answers what is on this machine. Monitoring answers what is out there across all of them. Surfaces when one device is in trouble; here when a tool is on forty.

Can it read what people type into AI tools?

Yes, if your administrators switch it on. Conversation titles and messages are separate switches, off by default, and turning either on needs a typed reason that is kept with the name of whoever turned it on. Everything collected lands in your own endlayer platform, read only by the people your administrators allow. We never see it.

What happens when I block a tool?

Your decision publishes as a new policy version. Devices with the tool start failing that rule, and a removal request appears for an admin. Nothing is deleted until a person approves it. “Not allowed” is softer: the tool fails the rule and stays installed.

Why does the MCP count leave out local servers?

Because the question is whether data can leave the device. A server with a network address is a way out; one that only runs on the laptop is not. Counting both would make the number bigger and less useful.

Why do you call it token cost instead of spend?

Spend is a figure on an invoice. This is token counts from your devices priced against a versioned table, so the page can say which table it used and name any model it had no price for.

Does it need a gateway, a proxy or a connector?

No. The device views need only the agent, and nothing changes on your network. Connecting Microsoft adds a directory tab to Apps, and only after you consent.

start with endlayer

Take control of the AI already in your company.

It is already installed on the laptops. You can see all of it by this afternoon.

activity4h slices
30d ago22d15d7dnow