Skip to main content
Agentic Use records what your coding agents actually did — the shell commands they ran, the MCP tools they called, and the skills they loaded.

What’s on the page

Sub-tabs

The active sub-tab is carried in the URL as ?tab=, so a link can open one directly. The MCP Actions lens is carried too: ?view=unsanctioned opens the Unsanctioned Usage side directly. A drilled-in server is carried too: ?tab=mcp_tool&server=<server name> opens that server directly, and ?group=<id> opens a group where your organization has servers grouped. Drilling in and returning by the MCP Actions breadcrumb both keep the address in step, so browser back and forward work through a drill-down.

Terminal Run — charts

Terminal Run — table

Initiator shows one of four states:

MCP Actions — MCP Servers

Charts: Top Actions by Server and Top Users. Selecting a bar in either applies it as a filter below.

MCP Actions — server detail

Selecting a row opens that server or group on its own. Four figures across the top — Total Logs, Avg Risk Score, High Risk Commands and Active Users — then Top Tools, Top Users and Activity Trend, and a Servers card where the row was a group holding more than one server, for narrowing to one inside it. Below those, the calls themselves:

MCP Actions — Audit Logs

A Tool Calls / Audit Logs switch on the server detail opens the raw call history: every MCP call to that server or group with its tool name, the developer who made it and when. Expand a call for the exact arguments sent and the output returned. Where your organization has connected-account signals, an External Domains figure joins the row above, counting the distinct domains this server’s MCP connections are bound to — those outside your whitelist where one is configured, otherwise all of them. Selecting it flips to Audit Logs narrowed to those connections, and the filter shows as a chip you can clear. In the list those calls carry a red marker; expanding one names the account’s domain and how it was classified. The full account is never shown.
Audit Logs may not be enabled for your organization. Where it is, it reads to Admins and Analytics Viewers — narrower than Agentic Use itself.

MCP Actions — Unsanctioned Usage

Skills

Invocations, Skills Used and Users for the period, then Invocations Over Time, Top Skills and By Tool. The All Skills table carries Skill, Invocations, Users, Tools, Categories, Risk and Last Used; a skill Unbound has not assessed shows as Not scanned.

Filters and controls

Time range

24 Hours · 3 days · 7 days · 1 month · 3 months · Custom Range Your choice is remembered between visits and applies to charts and table together. A custom range covers any window within the last 90 days; once one is applied, the menu’s Custom Range entry carries a .

Filters

Add Filter opens the dimensions available for the current sub-tab. Selections appear as chips and combine. Unsanctioned Usage drops Risk Levels, Initiator and Policies, since a blocked call carries none of them. Skills keeps User and adds its own Skill and Tool filters in place of the rest. Command Families lists the families your agents have run in the last 90 days.
What a Manager sees here is their own reports. Admin and Analytics Viewer read the whole organization; a Manager reads themselves and the people who report to them, and the User filter lists exactly those people. Department, Team Manager, Policies and Command Families do not appear in their Add Filter menu, since all four describe the organization rather than a team.

Command families

What you can do

Terminal run panel

Headed with the developer’s name and the run’s timestamp. View in Logs in the header opens the same activity in Logs. Marking a run helpful or unhelpful, with optional notes, tunes future classification.

MCP call panel

Unsanctioned call panel

Skill panel

Invocations, Users and Tools for the skill, then Invocations Over Time, By Tool, Top Users, the rendered Skill Content — one entry per version where several copies of a skill share a name, with a diff between them — and Recent Invocations listing when, who and through which agent.

Messages you may see

Common questions

How do I find a particular kind of command my agents ran? Analytics → Agentic Use → Terminal Run, then Add Filter → Command Families and tick the family — Read File for file reads, Cloud Destroy for teardown. Where do I see what files my agents read? The same route, filtering on Read File. Selecting a row shows the exact command and the prompt behind it. Where do I see MCP tool calls? The MCP Actions sub-tab, under the MCP Servers lens. Selecting a server opens its own view; the Audit Logs switch there shows every call to it, with the arguments sent and the output returned. How do I find out which policy stopped something? The Policy Match column names the policies a run matched, and the first links through to the policy. Why is a command marked as coming from the agent rather than the developer? The Initiator column records who chose the action. Processing means attribution is still resolving.