Find AI at every layer, not just the API.
Octic combines API, network, and kernel-level discovery into one map of your estate: AI agents, MCP servers, API endpoints, AI apps, packages, and processes.
- 2 of 8 are visible to an API-only inventory: support-triage-agent and the OpenAI API.
- Network traffic adds invoice-extractor, which calls the OpenAI API, and mcp-postgres-prod, a flagged MCP server with production database access.
- Kernel sensors on eng-ws-14 (Linux) and WIN-ENG-07 (Windows) add what runs on them: shadow-summarizer, a flagged AI agent with no owner that connects to mcp-postgres-prod, and Codex signed in with a personal account.
Sensors see what runs on each host
Install the Octic sensor on servers and engineer laptops. It sees the AI apps, packages, dependencies, and processes on each host, including AI agents that never touch an API you manage.
Linux and Windows are supported today. Coverage grows as you roll sensors out.
- eng-ws-14, Sensor LinuxHost. Approved.
- shadow-summarizer, AI Agent. Flagged.
- WIN-ENG-07, Sensor WindowsHost. Approved.
- Codex, Software Application. Flagged.
- ip-172-31-67-241, Sensor LinuxHost. Approved.
- openai 1.51.0, Software Package. Unreviewed.
- eng-ws-14 runs shadow-summarizer.
- WIN-ENG-07 runs Codex.
- ip-172-31-67-241 has package openai 1.51.0.
Network traffic shows what no inventory lists
Traffic analysis finds AI services that no inventory lists, such as an MCP server someone stood up without telling anyone, and the AI agents talking to it.
- invoice-extractor, AI Agent. Unreviewed. Found in network traffic.
- shadow-summarizer, AI Agent. Flagged. Found by kernel sensor.
- mcp-filesystem, MCP Server. Unreviewed. Found in network traffic.
- OpenAI API, Model API. Approved. Found via API.
- mcp-postgres-prod, MCP Server. Flagged. Found in network traffic.
- invoice-extractor connects to mcp-filesystem.
- invoice-extractor calls OpenAI API.
- shadow-summarizer connects to mcp-postgres-prod.
API connections and sensors land in one map
Octic connects to the platforms you already run to list known AI agents, MCP servers, and API endpoints, then matches them against what the sensors and the network see. Every finding lands in one graph: which AI agents call which models, which MCP servers they use, and which hosts they run on.
Discovery runs in the background. New AI agents and MCP servers show up as they appear, not at the next quarterly audit.
- eng-ws-14, Sensor LinuxHost. Approved.
- Claude Code, Software Application. Approved. Found by kernel sensor.
- payments-api, Code Repository. Approved. Found via API.
- Anthropic API, Model API. Approved. Found via API.
- ip-172-31-67-241, Sensor LinuxHost. Approved.
- support-triage-agent, AI Agent. Approved. Found via API.
- mcp-jira, MCP Server. Approved. Found via API.
- eng-ws-14 runs Claude Code.
- Claude Code commits to payments-api.
- Claude Code calls Anthropic API.
- ip-172-31-67-241 runs support-triage-agent.
- support-triage-agent connects to mcp-jira.
Discovery is where the loop starts
What discovery finds is a starting point. Trust gives it an owner and a state, Observe shows what it does at runtime, and Remediate turns what is wrong into a finding with an owner. Agentic fixes are coming late 2026.
Put your own estate on the map
Install a sensor on a Linux or Windows host and coding-agent sessions start showing up, with no extra setup. Connect your APIs and the rest of the map fills in.