> ## Documentation Index
> Fetch the complete documentation index at: https://docs.formal.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Monitor AI Usage

> See which AI clients, models, providers, MCP servers, and skills people use, and what policies they trigger

## Overview

The **AI Tools** section of the Control Plane includes six pages built from AI traffic that Formal proxies:

| Page | Shows |
| - | - |
| [Usage](https://app.formal.ai/ai-usage) | Sessions, requests, and tokens across every AI client and model |
| [Models](https://app.formal.ai/ai-models) | Every model in proxied AI traffic, with usage and policy activity |
| [MCPs](https://app.formal.ai/ai-mcps) | Every MCP server in proxied traffic, the tools agents call, and the tools it offers |
| [Skills](https://app.formal.ai/ai-skills) | Every skill loaded into agent context, against everyone it was offered to |
| [Applications](https://app.formal.ai/ai-applications) | Every AI client application, such as Claude Code or Cursor |
| [Providers](https://app.formal.ai/ai-providers) | Every LLM provider, such as Anthropic or OpenAI |

These pages require the **Logs** permission. They only read data. To act on what you find, use [Guardrails](/docs/guides/ai-governance/guardrails), the [Catalog](/docs/guides/ai-governance/overview#the-catalog), or [policies](/docs/guides/policies/introduction).

## Data Sources

| Page | Traffic it reads |
| - | - |
| Usage | LLM requests captured by the [Formal Endpoint](/docs/guides/client-apps/desktop-app) |
| Models, Applications, Providers, Skills | LLM requests from the Endpoint or from [LLM Resources](/docs/guides/core-concepts/resources/llm) on a Connector |
| MCPs | MCP JSON-RPC requests to MCP Resources, such as servers on the [MCP gateway](/docs/guides/core-concepts/connectors/mcp-gateway) |

If a page is empty, see [Capture AI Traffic](/docs/guides/ai-governance/overview#capture-ai-traffic).

## Usage

The **AI Usage** page summarizes Endpoint AI activity for **Last 24 Hours**, **Last 7 Days**, or **Last 30 Days**. The header shows **Number of Sessions**, **LLM Requests**, **Triggered Policies**, and **Insights Count**. **LLM Requests** and **Triggered Policies** link to the matching logs, and **Insights Count** links to [Insights](/docs/guides/observability/insights).

* The **Usage** tab charts sessions, requests, triggered policies, and risks over time. It breaks activity down by application, provider, model, and user, and lists recent sessions.
* The **Security** tab shows triggered policy actions and ranks users by requests, sessions, and triggered policies.

## Models, MCPs, Skills, Applications, and Providers

These pages cover the last 30 days. Each one has a **Usage** tab with key figures and charts, and an inventory tab with one row per item. Click a row to open its detail page, with links to the matching logs.

Every inventory includes these columns: **Users (30d)**, **Requests**, **Policy Hits**, **First Seen**, and **Last Used**. Show **Users (7d)**, **Sessions**, and **Devices** from the column picker. Pages for LLM traffic also show **Tokens**.

| Page | Key figures | Extra columns |
| - | - | - |
| Models | Models in use, tool-calling requests | **Provider** |
| Applications | Applications in use, devices | **Models** |
| Providers | Providers in use, failed requests, authentication failures | **Models** |
| MCPs | Tool calls, tool discoveries, Formal Resources | **Tool Calls**, **Tools Used** |
| Skills | Skill loads, users loading skills, policy hits on loads | **Available To**, **Loaded By** |

The MCPs page identifies a server by its hostname and URL path. The Skills page only covers Claude Code traffic, because Formal detects skills in Claude Code requests only. It counts a load for each request that carries a skill's instructions, so a skill counts again on every later turn of the same conversation.

## Next Steps

<CardGroup cols={2}>
  <Card title="Shadow AI" icon="binoculars" href="/docs/guides/ai-governance/shadow-ai">
    Review MCP servers and skills outside the Catalog
  </Card>

  <Card title="Insights" icon="lightbulb" href="/docs/guides/observability/insights">
    Review AI-generated security findings
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.