Analytics & reporting

Understand every supervised project

The same decisions that protect your machine become project-level activity, security posture, and verifiable evidence. See what is running, where risk concentrates, and which policies intervene.

Local source of truth · operand-free team sync · visible coverage

One view of activity and risk

Group supervised operations by project, tool, and session. See the verdict, score, and filter patterns behind the totals.

grith team analyticsexample datadata through 14:03 UTC · 3 devices current
Actions
0
Projects
0
Queued
0
Denied
0
Project activity · 30 days
ProjectActionsSessionsAllowedAvg score
grith2,3102297.1%1.6
grith-website2,0481898.0%1.3
grith-docs1,4841296.4%1.9
Decision split
98.7%allowed
Allow5,768
Queue63
Deny11

Answers you can act on

Grith measures the operations seen at the supervision boundary, then rolls them up without sending their operands to the team dashboard.

01

Project activity

What is each project doing?

Compare actions and exact session counts by project and supervised tool. Follow allow, queue, and deny rates without asking each agent to report on itself.

ActionsSessionsSupervised toolVerdict trend
02

Security posture

Where is risk accumulating?

See score distributions, risky operation categories, filter effectiveness, and the newest queue, deny, canary, and coverage-gap events.

Average scoreTop filtersHigh-risk eventsRisk trend
03

Coverage and freshness

Can you trust the picture?

The dashboard shows how far each device has materialised and synced, including partial days, stale devices, disabled sync, and explicit gaps.

Data throughDevice stateChain healthGap count
Model usage and cost

Cost in the context of the work

When Grith receives model usage metadata, it attributes prompt and output tokens and estimated cost by provider, model, project, and session. Historical estimates retain the price source and version used at the time.

Today that data comes from the built-in agent. Wrapped third-party agents still produce the complete project and security view, but their provider token usage is not exposed to Grith.

Current coverage
Supervision modeProject securityTokens and cost
grith run

Built-in agent with direct provider usage metadata

IncludedIncluded
grith exec

Claude Code, Codex, Aider, and other wrapped agents

IncludedNot currently captured
Governance and evidence

Evidence, not a compliance badge

Grith helps teams collect evidence that agent activity was observed, evaluated, and retained. It does not certify an organisation or determine whether a control has been satisfied.

Local source of truth

Analytics is materialised from the local hash-chained audit log. If a projection is rebuilt, the underlying audit records are not rewritten.

Verifiable daily archives

Pro archives contain one structured, operand-free row per operation. Grith checks the checksum, row count, and rebuilt result against what the server accepted.

Coverage that shows its gaps

Freshness, partial-day, stale-device, disabled-sync, and gap states stay visible instead of silently presenting an incomplete record as complete.

Privacy-preserving team view

Commands, paths, prompts, responses, code, file contents, payloads, and environment values have no cloud analytics fields. Project names are uploaded in clear text.

Use the record in internal-control, SOC 2, or NIST AI RMF workflows after mapping it to your own systems, scope, and control design.

Start with a local source of truth

Community includes seven days of local decision analytics, audit health, and recent security events. Pro adds 30 and 90-day team rollups and verifiable daily archives.