Technology · Endpoint Observation

Know which AI runs on every device.

People adopt AI tools faster than any approval process can follow. Endpoint Observation shows what is installed, what is used, and what company data leaves through it, so policy can be based on what actually happens.

Device inventory · excerpt
laptop-042IDE assistant · approved chat · unapproved desktop app
laptop-118approved chat · browser extension (AI summarizer)
laptop-203local model runner · CLI agent started from a script
laptop-311approved chat only
policy2 of 4 devices out of policy · 1 with data leaving to an external model API
Illustrative excerpt.
Questions it answers

The questions IT and security get asked, with answers instead of surveys.

  • 01Which AI tools are installed across our fleet, and which of them are actually used?
  • 02Who is using tools we have not approved, and on which devices?
  • 03What company data has been sent to external model APIs, from where, by whom?
  • 04Which devices run local agents or model runners that nobody set up centrally?
  • 05Is our AI policy followed in practice, per department and per device?
What it sees

Every way AI arrives on a device.

Most of it never passes through procurement. Endpoint Observation finds it from what runs, not from what was requested.

AI desktop apps

Chat and assistant apps installed by the user, including free tiers with different data terms than the paid plan you approved.

IDE assistants and plugins

Coding assistants and their extensions, which read source code by design and often more than that.

Browser extensions

Summarizers, writing aids and page assistants that see every page the user opens, including internal tools.

Local model runners

Models running on the device itself. Cheap, private, and invisible to network-based controls.

CLI and background agents

Agents started from a terminal or a script that keep running after the person moves on.

Data movement

Files and text leaving the device toward model APIs, tied to the tool, the user and the time.

Example · a finance team

The approved tool was fine. The free one was not.

The company approved one AI chat tool with a data agreement. An analyst preferred a free desktop app for questions about spreadsheets. Nothing in the existing stack noticed, because the app looked like any other program and the traffic looked like any other HTTPS.

Endpoint Observation listed the app on the device, matched its use to the finance policy, and showed three quarterly close files leaving toward an external model API during the quiet period before results.

The fix took a day. The report to legal had timestamps instead of estimates.

Finding · laptop-042
userfinance analyst
toolAI desktop app · free tier · installed 41 days ago
usageactive 9 of last 10 workdays · 2.1 h/day average
dataQ3-close.xlsx · revenue-bridge.xlsx · board-draft.docx
policyfinance: approved tools only · violated
riskHigh · pre-disclosure financial data on a third-party service
nextrestrict app · notify user · document for legal
Illustrative finding.
What you get

Four things you did not have before.

Inventory

Every AI tool, per device

Installed and used, with versions and first-seen dates. Updated continuously, not once a quarter.

Usage

Who uses what, how much

Real usage per tool and department, so policy can follow what people actually rely on.

Data risk

What leaves, and where to

Files and text sent to model APIs, tied to tool, user and time, ranked by sensitivity.

Policy

Rules that are checked, not hoped for

Approved and blocked tools per group, with violations flagged and the option to enforce per device.

Endpoint Observation works alongside the device management you already run. The exact setup depends on your fleet and your operating systems. We walk through it in the demo, with your environment on the table.

Demo

Find out what runs on your devices.

Bring one team you are unsure about. We will show you what an inventory built from real usage looks like.

Schedule a demo