Skip to main content

Overview

The AI Tools section of the Control Plane includes six pages built from AI traffic that Formal proxies: These pages require the Logs permission. They only read data. To act on what you find, use Guardrails, the Catalog, or policies.

Data Sources

If a page is empty, see Capture AI Traffic.

Usage

The AI Usage page summarizes Endpoint AI activity for Last 24 Hours, Last 7 Days, or Last 30 Days. The header shows Number of Sessions, LLM Requests, Triggered Policies, and Insights Count. LLM Requests and Triggered Policies link to the matching logs, and Insights Count links to Insights.
  • The Usage tab charts sessions, requests, triggered policies, and risks over time. It breaks activity down by application, provider, model, and user, and lists recent sessions.
  • The Security tab shows triggered policy actions and ranks users by requests, sessions, and triggered policies.

Models, MCPs, Skills, Applications, and Providers

These pages cover the last 30 days. Each one has a Usage tab with key figures and charts, and an inventory tab with one row per item. Click a row to open its detail page, with links to the matching logs. Every inventory includes these columns: Users (30d), Requests, Policy Hits, First Seen, and Last Used. Show Users (7d), Sessions, and Devices from the column picker. Pages for LLM traffic also show Tokens. The MCPs page identifies a server by its hostname and URL path. The Skills page only covers Claude Code traffic, because Formal detects skills in Claude Code requests only. It counts a load for each request that carries a skill’s instructions, so a skill counts again on every later turn of the same conversation.

Next Steps

Shadow AI

Review MCP servers and skills outside the Catalog

Insights

Review AI-generated security findings