Project activity
What is each project doing?
Compare actions and exact session counts by project and supervised tool. Follow allow, queue, and deny rates without asking each agent to report on itself.
The same decisions that protect your machine become project-level activity, security posture, and verifiable evidence. See what is running, where risk concentrates, and which policies intervene.
Local source of truth · operand-free team sync · visible coverage
Group supervised operations by project, tool, and session. See the verdict, score, and filter patterns behind the totals.
Grith measures the operations seen at the supervision boundary, then rolls them up without sending their operands to the team dashboard.
What is each project doing?
Compare actions and exact session counts by project and supervised tool. Follow allow, queue, and deny rates without asking each agent to report on itself.
Where is risk accumulating?
See score distributions, risky operation categories, filter effectiveness, and the newest queue, deny, canary, and coverage-gap events.
Can you trust the picture?
The dashboard shows how far each device has materialised and synced, including partial days, stale devices, disabled sync, and explicit gaps.
When Grith receives model usage metadata, it attributes prompt and output tokens and estimated cost by provider, model, project, and session. Historical estimates retain the price source and version used at the time.
Today that data comes from the built-in agent. Wrapped third-party agents still produce the complete project and security view, but their provider token usage is not exposed to Grith.
grith runBuilt-in agent with direct provider usage metadata
grith execClaude Code, Codex, Aider, and other wrapped agents
Grith helps teams collect evidence that agent activity was observed, evaluated, and retained. It does not certify an organisation or determine whether a control has been satisfied.
Analytics is materialised from the local hash-chained audit log. If a projection is rebuilt, the underlying audit records are not rewritten.
Pro archives contain one structured, operand-free row per operation. Grith checks the checksum, row count, and rebuilt result against what the server accepted.
Freshness, partial-day, stale-device, disabled-sync, and gap states stay visible instead of silently presenting an incomplete record as complete.
Commands, paths, prompts, responses, code, file contents, payloads, and environment values have no cloud analytics fields. Project names are uploaded in clear text.
Use the record in internal-control, SOC 2, or NIST AI RMF workflows after mapping it to your own systems, scope, and control design.
Community includes seven days of local decision analytics, audit health, and recent security events. Pro adds 30 and 90-day team rollups and verifiable daily archives.