Search the graph. Follow what connects.
Every AI agent, MCP server, coding agent, package, host, repository, and model API Octic finds sits on one graph, with its owner and trust state. Search by name or ask in plain language, then follow what connects, hop by hop.
Acme Corp's graph, asked which MCP servers have no owner, with the answer opened 3 hops out
Question: Which MCP servers have no owner?
eng-ws-14 reaches it in 2 hops, through an AI agent nobody owns.
mcp-postgres-prod
MCP Server- Trust
- Flagged
- Owner
- No owner found
- Found in
- Network traffic
- Relations
- 1 direct, 5 within 3 hops
- Hop 1shadow-summarizerconnects tomcp-postgres-prod
- Hop 2eng-ws-14runsshadow-summarizer
- Hop 2shadow-summarizerusesopenai 1.51.0
- Hop 3eng-ws-14runsClaude Code
- Hop 3ip-172-31-67-241has packageopenai 1.51.0
On the map, shadow-summarizer connects to mcp-postgres-prod; eng-ws-14 runs shadow-summarizer; shadow-summarizer uses openai 1.51.0; eng-ws-14 runs Claude Code; ip-172-31-67-241 has package openai 1.51.0.
Expand upstream or downstream, one hop at a time
Select a node to see its trust state, owner, and direct relations: what runs it, what it calls, and what it connects to. Expand it one hop, or right-click to expand upstream, downstream, or by one kind of relation.
Relations run both ways, so you can trace which AI agents depend on an unreviewed package, or who owns each node along a path.
- Starting from WIN-ENG-07, a Windows workstation, and following one relation at a time.
- Hop 1: WIN-ENG-07 runs Codex.
- Hop 2: Codex calls OpenAI API.
- Hop 3: invoice-extractor calls OpenAI API.
- Hop 4: invoice-extractor connects to mcp-filesystem.
- mcp-filesystem is 4 hops from WIN-ENG-07.
Filter by kind or trust state
Narrow the graph to AI agents, MCP servers, repositories, APIs, or one trust state. The graph stays in place and everything else dims, so a filtered view keeps the relations around it.
Save the views you come back to.
- eng-ws-14, Sensor LinuxHost. Approved.
- WIN-ENG-07, Sensor WindowsHost. Approved.
- ip-172-31-67-241, Sensor LinuxHost. Approved.
- Claude Code, Software Application. Approved.
- Codex, Software Application. Flagged.
- Anthropic SDK 1.3.0, Software Package. Approved.
- openai 1.51.0, Software Package. Unreviewed.
- shadow-summarizer, AI Agent. Flagged.
- invoice-extractor, AI Agent. Unreviewed.
- mcp-postgres-prod, MCP Server. Flagged.
- mcp-filesystem, MCP Server. Unreviewed.
- support-triage-agent, AI Agent. Approved.
- mcp-jira, MCP Server. Approved.
- Anthropic API, Model API. Approved.
- OpenAI API, Model API. Approved.
- payments-api, Code Repository. Approved.
- eng-ws-14 runs shadow-summarizer.
- WIN-ENG-07 runs Codex.
- Codex calls OpenAI API.
- shadow-summarizer connects to mcp-postgres-prod.
- shadow-summarizer uses openai 1.51.0.
3 flagged: 1 coding agent, 1 AI agent, and 1 MCP server. None has an owner.
Reveal everything downstream
Reveal a node’s downstream chain to open everything it leads to: the AI agents a host runs, the MCP servers and model APIs they connect to, and the packages they use.
From one engineer’s workstation, that includes an MCP server with production database access, two hops out, through an AI agent nobody owns.
- eng-ws-14, a Linux workstation with a sensor, is the starting point.
- 1 hop out: eng-ws-14 runs Claude Code.
- 1 hop out: eng-ws-14 runs shadow-summarizer.
- 2 hops out: Claude Code calls Anthropic API.
- 2 hops out: Claude Code commits to payments-api.
- 2 hops out: shadow-summarizer connects to mcp-postgres-prod.
- 2 hops out: shadow-summarizer uses openai 1.51.0.
eng-ws-14 reaches 6 nodes within 2 hops. 2 are flagged and 1 is unreviewed.
Where this sits in Discover
Integrations and network and kernel-level discovery find what’s in your estate. The graph explorer is where it all lands, and where you search and follow it.
Back to DiscoverSearch your own estate’s graph
Install a sensor on a Linux or Windows host and connect your APIs. Every AI agent, MCP server, and package Octic finds lands on the graph, with its relations, ready to search.