Skip to content
Session Intelligence

Full Conversation Replay - Every Prompt, Tool Call, and File Access

Reconstruct complete Claude Code sessions turn by turn, with the file operations, shell commands, MCP connections, and per-turn cost that came with them.

The Problem

"Something Happened" Is Not an Investigation

An AI agent deleted a production config file. A credential appeared in a public repository. A vulnerable package shipped to production. In each case the question is the same: what exactly did the agent do, what was it asked to do, and what changed as a result?

Process-level telemetry cannot answer that. It shows a binary that ran and files that changed. It cannot show the prompt that triggered the change, the tool call the model chose, or the MCP server that received the data.

How It Works

Session Reconstruction from Deep Telemetry

Sessions are reconstructed on the endpoint and streamed to the dashboard with sub-second latency. Nothing is sampled and nothing is summarized away.

  • Complete conversation timeline - user prompts, assistant responses, and every tool call in sequence
  • File operations - every read, write, and edit performed by the agent, with path and context
  • Shell command logging - full command text, working directory, and execution context
  • MCP server connections - which external tool servers the AI reached and what it sent
  • Subagent relationships - parent/child session mapping when the AI spawns background agents
  • Cost attribution - per-turn input, output, cache read, and cache write tokens with model-aware pricing
  • Session metadata - duration, project and repo context, model selection, git branch

Live Floor

The Live Floor shows every active AI session across the fleet as it happens: who is running what, in which repo, on which model, with live token burn. Sessions stream in with sub-second latency, so an in-progress incident is visible while it is still in progress.

What You See

The Forensic Record

AI session list grouped by tool, device, and day, each row showing risk score, session count, secret findings, and cost
AI sessions grouped by tool, device, and day - each group leads with risk score, session count, secret findings, and cost.
Technical Specification

Captured Per Session

DimensionDetail
Per turnPrompt text, response text, tool invocations, input/output/cache-read/cache-write tokens, model, computed cost
File operationsRead, write, and edit events with path and surrounding context
Shell commandsFull command text, working directory, execution context
MCPServer destination and payload metadata for each connection
SubagentsParent/child session mapping for background agents
Session metadataDuration, project/repo, git branch, model selection, user, device
TransportEncrypted end to end with mutual TLS; buffered locally and replayed on reconnect, so an offline laptop loses nothing
Retention7 days (Community) · 30 days (Team) · 90 days (Business) · custom (Enterprise)
Privacy by design: the platform collects metadata about AI usage patterns and policy-relevant findings, not wholesale copies of proprietary code.
Compliance Mapping

Controls This Evidences

ISO A.8.16
Monitoring activities - real-time AI conversation telemetry across every endpoint
NIST AU-2
Event logging - AI agent actions recorded as auditable events
NIST AU-6
Audit record review, analysis, and reporting
HIPAA §164.312(b)
Audit controls - record and examine activity in systems with ePHI

See Kraitos AIDR in Action

Deploy in 60 seconds. Get answers in 24 hours. Stop guessing what your AI-augmented organization is doing.

[email protected]kraitos.io