The Activity tab in AI Detection & Response provides a continuous feed of every AI tool access event across managed endpoints. Use this tab to monitor ongoing behavior and identify endpoints actively using ungoverned tools over the past 7 days. Click the drop-down in the top-right to select a different time frame.
Activity feed
Each record on the table represents an endpoint with AI tool activity. At the top are 3 filters that help you quickly identify endpoints with unauthorized, unclassified, or authorized tools.
The table below it displays the following information:
| Column | Description |
|---|---|
| AI Tool | Name of the tool. |
| Domain | Number of domain requests made by the tool. |
| Endpoint | The device with AI tool activity. Click on the endpoint name to get full details of its AI activity. |
| Group | The Nebula group the endpoint is assigned. |
| OS | The endpoint's operating system type. (Workstation or Server) |
| Policy | The Nebula policy assigned to the endpoint's group. |
Viewing endpoint details
Click any endpoint name to open the detail slide-out. This shows the following:
- Request Summary: A quick snapshot of total requests, broken down into authorized, unauthorized, and needs review.
- Tool Usage: A table listing AI tools detected on the endpoint. For each tool, it shows the last detected version, whether it's installed, the number of domain requests, and its governance status.
- Policy Period History: A timeline showing the Nebula policies previously applied to this endpoint. Each entry includes a bar chart visualizing the ratio of authorized to unauthorized requests during that policy period.
Notes
AI Web activity is not real-time and is updated in the console within a few minutes.
Installed AI tools are surfaced by an asset scan, so if an AI app is newly installed, an asset scan must be run for it to be reflected.
Back to AIDR guide.