Skip to content
Monitor

See Every AI Tool, Session, Token, and Dollar

Real-time visibility across the fleet: which AI tools run where, what each session actually did, where the data went, and what all of it costs.

Detection Detail

The Five Layers

DiscoveryFilesystem scanning for config directories, VS Code and JetBrains extensions, and process names - 14 AI tools detected by name
NetworkConnection monitoring identifies 25+ cloud LLM APIs and 7 local inference servers by destination
BehavioralBehavioral heuristics recognize how AI tools act - catching unknown and custom tools no signature list has heard of
TelemetryDeep session telemetry for Claude Code - full conversation replay, token tracking, MCP visibility
DependencyDependency monitoring across 9 package formats, with known vulnerabilities flagged automatically
What You See

The Monitoring Surface

AI session list grouped by tool, device, and day, each row showing risk score, session count, secret findings, and cost
AI sessions grouped by tool, device, and day - each group leads with risk score, session count, secret findings, and cost.
Per-device AI tool inventory listing each detected tool with version, first seen, and last seen dates
Per-device AI tool inventory - every tool found by name or by network destination, with version and first and last seen.
Cost and usage analytics with total cost, cache hit ratio, cost over time chart, and per-developer breakdown
Cost and usage - spend attribution by developer, repo, model, and team, with cache hit ratio and a 30-day trend.
AI egress console listing destinations with provider, sanctioned or shadow classification, connection volume, and sanction or block actions
AI egress - every destination classified sanctioned or shadow, ranked by connection volume, with one-click sanction or block.
How It Works

From Endpoint to Dashboard

  1. Step 01

    Collect locally

    The agent observes AI tools, sessions, connections, and dependencies on the endpoint itself.

  2. Step 02

    Stream securely

    Telemetry streams over an encrypted, mutually authenticated channel, buffered locally and replayed on reconnect - an offline laptop loses nothing.

  3. Step 03

    Process and attribute

    The ingestion service maps activity to user, team, device, repo, and model, then prices it.

  4. Step 04

    Surface in seconds

    Sessions appear on the Live Floor with sub-second latency; inventory refreshes on its own cadence.

Compliance

Controls This Pillar Satisfies

NIST CM-8
System component inventory - AI tools, software, hardware, and extensions
NIST SI-4
System monitoring - continuous behavioral and network monitoring
ISO A.8.16
Monitoring activities across every endpoint
SOC 2 CC7.2
System monitoring with real-time alerting

See Kraitos AIDR in Action

Deploy in 60 seconds. Get answers in 24 hours. Stop guessing what your AI-augmented organization is doing.

[email protected]kraitos.io