Overview
The AI Tools section of the Control Plane includes six pages built from AI traffic that Formal proxies:
These pages require the Logs permission. They only read data. To act on what you find, use Guardrails, the Catalog, or policies.
Data Sources
If a page is empty, see Capture AI Traffic.
Usage
The AI Usage page summarizes Endpoint AI activity for Last 24 Hours, Last 7 Days, or Last 30 Days. The header shows Number of Sessions, LLM Requests, Triggered Policies, and Insights Count. LLM Requests and Triggered Policies link to the matching logs, and Insights Count links to Insights.- The Usage tab charts sessions, requests, triggered policies, and risks over time. It breaks activity down by application, provider, model, and user, and lists recent sessions.
- The Security tab shows triggered policy actions and ranks users by requests, sessions, and triggered policies.
Models, MCPs, Skills, Applications, and Providers
These pages cover the last 30 days. Each one has a Usage tab with key figures and charts, and an inventory tab with one row per item. Click a row to open its detail page, with links to the matching logs. Every inventory includes these columns: Users (30d), Requests, Policy Hits, First Seen, and Last Used. Show Users (7d), Sessions, and Devices from the column picker. Pages for LLM traffic also show Tokens.
The MCPs page identifies a server by its hostname and URL path. The Skills page only covers Claude Code traffic, because Formal detects skills in Claude Code requests only. It counts a load for each request that carries a skill’s instructions, so a skill counts again on every later turn of the same conversation.
Next Steps
Shadow AI
Review MCP servers and skills outside the Catalog
Insights
Review AI-generated security findings