AI-tool discovery
Find the AI tools your team actually uses — the desktop app detects them on each machine and reports only the matches to your own server. Detected, not observed. Sovereign by design.
Discovery finds the AI tools your people already use that nobody registered. The desktop app, installed on a machine, identifies the AI apps and command-line tools present there, drops everything non-AI on the device, and reports only the AI matches to your own server. They land in the Registry badged detected — not observed, feeding the same audit log as everything else.
There are two setup shapes: a simple install link each person opens once to self-enrol their machine, and an MDM managed mode for a silent fleet (IT ships the app plus a config profile; machines self-enrol on a timer). Both are detected-not-observed, and both are sovereign — findings go only to your own self-hosted server, never a vendor cloud. Operators set both up from Oversight → Registry → Connect → Endpoint discovery.
Ceiling — This is detected, not observed. The only thing transmitted is which AI provider, running or installed, and when — never a process list, browsing, file or prompt content, or what the tool did. Coverage is the enrolled, alive fleet only: a machine without the app isn't seen this way, and AI used inside a browser tab is covered separately by the extension below. A silenced or offline machine shows as stale — visible, never assumed clean.
On your own machine#
You don't need a link to set up your own. In the desktop app, open the account menu → "My device & privacy" → "What I've reported" to see the AI tools found on this machine, then enroll and report — attributed to you. It's reachable from the tray at any time; quitting stops the sensor and the machine shows as stale.
Browser tabs#
The desktop app sees AI apps installed on a machine, but not AI used in a browser tab (the browser hides the site from the OS). A small Chrome extension closes that gap: it classifies AI web tools on-device by hostname only, drops everything else, and reports just the matches to your own server — same Registry, still detected, not observed.
Ceiling — The extension knows which AI tool is open in a tab — never the pages, the text you type, what the AI generates, your history, or your other tabs. It only reads a hostname, and it never blocks a page. Coverage is the browser profiles where it's installed.
Who uses what — attribution#
Enrollment ties each machine to a real person, so the Registry answers the question the feature exists for: which AI tools do our people use, so we can decide — allow, govern, or ask for removal. Expand a tool to see the machines and people it's on, or pivot to a By person view. Claim a detected tool to assign its owner, Allow one that's accepted but unowned, or Dismiss a false positive — so every real tool ends up in a decided state rather than flagged forever.
Where the tool is one damn.dev can govern, the same expanded view offers to connect it. On the machine that has it, that's one click. From anywhere else it's a link you send its owner — connecting writes a file on someone's computer, so it happens there, with their knowledge, never pushed from a console.
Ceiling — Attribution reports which AI tools are present on whose machine — existence, never what that person did, and never any content. It's governance visibility, gated to operators. Scheduled reporting of a person's tool usage is exactly the kind of thing your works-council / privacy process should sign off on; that disclosure is yours to make. The product's job is the on-device drop-at-source, the transparency panel every employee can see, and a sovereign destination.
From discovered to governed#
Discovery tells you a coding agent exists on a machine. Connecting it goes further: the agent reports each action into your audit trail, and your rules can gate it.
You decide when you create the onboarding link. Choose to govern their machine and the app sets both up in one step — the person sees a plain-language disclosure of exactly what is reported, on their own machine, before anything starts. Nothing is ever applied that they weren't shown. Leave it off and the machine stays discovery-only.
Note — Telling your people is still your job. In some jurisdictions it's a formal one — France's works-council consultation, for example. The app's disclosure is not a substitute for that process.
Ceiling — Connecting moves a tool from detected (it exists) to observed (it reports its actions) and best-effort gated (rules may deny an action). It never reads prompts, code, responses, or file contents, and it is not containment — the gate is best-effort and can be bypassed. It writes only the user's own config, with no elevated privileges, and disconnecting fully reverses it.
Set up a fleet#
Fleet tokens, the install link, the MDM config, and per-machine enrolment are all driven from Oversight → Registry → Connect → Endpoint discovery, which generates exactly what you hand to your MDM. For a managed fleet rollout across Jamf / Intune / Kandji, talk to us — we'll help scope the profile.
Note — No keystrokes, screens, files, clipboard, env vars, or browsing history ever leave a machine — everything non-AI is filtered on the device before anything is sent. Reports go only to your own self-hosted server, never a vendor cloud.
Next#
- Governing AI you don't run — connectors and honesty labels.
- Oversight & the Registry — where detected tools appear.