AI Activity

AI → AI Activity lists every AI application in use in a project: the Secure60 agents that run in it, the applications a Secure60 AI Protector guards, and AI services found in network logs that nobody has registered. The page has three tabs:

The time range at the top right applies to every tab. The tab, range and filters are held in the URL, so a view can be shared as a link.


Overview

The AI Activity Overview tab for the last hour: KPI tiles, a banner naming one unregistered AI application, and the flow chart from team to application to model provider

KPIs

Tile Meaning
AI applications Applications with AI activity in the window, split into known (registered) and not reviewed
Unknown AI Applications seen in the data with no registered entity, or with the state Discovered. Click to filter the list to them
People using AI Distinct identified users across all applications
AI calls Protector calls in the window, plus the number of Secure60 agent sessions
Blocked Calls a guardrail refused (policy in Protect mode)
Suspicious Calls with a risk score above zero
Unprotected Share of AI calls that no Protector saw; shown as a dash when calls outside a Protector are not measured

When an application is in use and nobody has registered it, a banner names it with a Review discovered button.

Who uses what, and where it goes

The flow chart runs from the people calling AI, through the application, to the model provider. The left column is grouped by one of:

Pivot Groups calls by
Team (default) The user’s entity groups. A user belongs to a team when their user entity is in a group on the Entities page; a user in two groups is counted in both, and a user in none is shown as No team
User user_name
Source IP ip_src_address
Host host_name
Country the source country
Protector the Protector group that handled the call

Each column shows the top values and folds the rest into Others; calls with no identified user are shown as Unidentified. The provider for a Protector application comes from its backend’s upstream URL or its AI provider setting. The colour of each application marks how it is known: protected, Secure60 agent, detected on the network or from a vendor feed, discovered and not registered, or prohibited. Clicking an application opens its audit trail.

How we know

The How we know panel: share of AI activity by source for the Secure60 Protector, Secure60 agents, vendor audit logs and network and endpoint, each with what it sees and misses and its connected feeds

This panel shows the share of AI activity seen by each source — Secure60 Protector, Secure60 agents, vendor audit logs and network and endpoint — with what each source sees and misses and the feeds connected to it (Protector backends, agents, network-detected applications with their last-seen time). Manage or + Connect opens the page where that source is configured. Network numbers are tracking sightings, which grow with the collector’s export interval; they size the bar and are not counted as calls. Discover AI Applications describes each source.

Lifecycle and applications

The Lifecycle panel counts the applications in each state; clicking a state filters the applications list to it. Secure60 agents carry no lifecycle state and are counted under No state.

The Applications table: a discovered network application, a prohibited network application, a protected application under review and a restricted protected application, with users, activity, calls, blocked, suspicious and visibility

The Applications table lists unknown applications first. Each row shows the state, owner, users, a stacked activity sparkline, calls (sessions for Secure60 agents, sightings for network applications), blocked and suspicious counts, and visibility:

Visibility Source Content available
Full content Secure60 AI Protector Prompt, new messages, reply, findings, model and tokens
Full steps Secure60 agent Every step, tool call and decision
Metadata Vendor audit logs Who, which application, which files
Network only AI Traffic Detection parser template Destination, host, user and volume

Clicking a row opens the application’s audit trail. The details button at the end of the row opens the application panel.

Application panel

The application panel for HR Policy Bot: lifecycle stepper at Restricted with the reason, allowed group and who set it, the lifecycle actions, how it was found, provider, registered entity, one hour of activity and recent sessions

The panel shows:

An application that is not registered yet shows Not registered yet: choosing a state registers it. Choosing a state creates the app entity with context.class = "ai".


AI Audit Trail

The AI Audit Trail tab in Sessions view: search box, a histogram of sessions by outcome, filters by source, application, decision and violation, and a table of Protector and Secure60 agent sessions with user, steps, tokens, decision and risk

The trail is built for volume: server-side paging, newest first.

Each row shows the time, application, user, a session summary (model calls and model, or the agent and the threat or hunt it worked), steps, tokens, duration, decision and risk. Rows with a risk score are marked on the left edge. Token counts appear for third-party calls only; Secure60 agent sessions never show tokens or model.

Calls with no session header are grouped by a session id the Protector derives from the conversation, so a conversation stays together without client changes. The session view shows whether the id came from the header or was derived.

Session view

Clicking a session opens it full width.

A Support Assistant session in the session view: header with application, user from header, tokens, model and session id; the system prompt with its hash; a timeline of model calls, tool calls and guardrail steps; the step list; and the second model call with two PII findings in a tool result, the match highlighted, the text as sent on with mask tokens, and the model's response
An Engineering Copilot session with four secret_leak findings: the finding detail names the aws_secret_key rule and the matching key is highlighted in the user message

Where the Protector records the position of a match (personal data, secrets and the prompt-injection phrase list), the matched text is highlighted; otherwise the whole segment is marked. Under the masked capture mode the highlight falls on the mask token. Newer and Older step through sessions; Copy link copies a link to the session.

A network-detected application’s trail lists its proxy, DNS or firewall events instead of sessions, marked Detected on the network · no content; rows without content show We can see that this happened, not what was said. Secure60 agent sessions show each step, tool call and decision, without model or token counts.


Watch

The Watch tab's lifecycle cards: Discovered, Under review, Sanctioned, Restricted, Prohibited and Retired, each with what it means for detection

Watch states what each lifecycle state means for detection, lists the rules from AI rule groups deployed on the project with their group, score and status, and lists the Secure60 agents deployed on the project. With no AI rule group deployed, it links to Detection Rules to deploy the AI Governance and AI Protector packs.


Back to top