Observability for AI agents: see every agent, watch every action, prove all of it.
CompFly builds the live picture of every AI agent you run, then turns that picture into evidence.
Unknown agents stop being unknown.
Discovery connects read-only to the platforms where your agents already live: the major model and agent platforms, code repositories, and enterprise SaaS. It returns every agent it finds, mapped to its models, tools, MCP servers, knowledge sources, memory, and sub-agents. Each one gets an owner and a risk tier.
Shadow AI
The AI nobody registered
Unregistered AI usage surfaces without any registration step, split into two lists: AI agents and direct chatbot usage. Each finding carries a risk score, a confidence level, and the detection evidence behind it, including where sensitive data was sent. One click brings a discovered agent under governance.
Risk tiering
Strictness that matches the stakes
Every agent is classified into a regulatory risk tier, derived from what it can reach and what it can do. The tier sets how strict its controls default to and how hard Simulation tests it. High-tier agents require human oversight. Unacceptable ones are blocked from deployment.
Every agent, down to its bill of materials.
One profile answers every question about an agent: its identity and keys, its bill of materials (every model, tool, MCP server, skill, knowledge source, and sub-agent, each marked sanctioned, unsanctioned, or pending), its effective controls, its risk tier with the reasoning behind it, and how it actually behaves.
- The org-wide map. Zoom out and the same data becomes a live map of agents, their owners, and the infrastructure they share.
- Blast radius in plain language. Click any node and get the answer directly, no query language required.
- Ownership gaps. Agents with no accountable owner stand out, before an incident makes the gap obvious.
- Concentration risk. The one model or MCP server half the fleet quietly depends on is visible before it becomes an outage.
Blast radius, on click
“If this tool fails, which agents across which departments are affected.”
illustrative topology · amber = shared dependency flagged for review
A live picture of every session.
Every agent session, live and historical, in one stream. Status at a glance: clean, live, denied, and denied-but-observed for agents still in learning mode. Open a session and you get the request timeline and which controls fired and why.
- expense-assistantFinancecleanCompleted, no controls fired
- support-copilotCustomer ServiceliveIn progress, timeline streaming
- data-sync-agentPlatformdeniedTool call stopped before execution
- onboarding-agentHRdenied · observedLearning mode: rule matched, allowed and logged
Drift, flagged the moment it starts.
CompFly learns a baseline per agent from the tools it calls and the arguments it passes, then compares live behavior against it. Drift is flagged in real time and routed where you work: in-product alerts, Slack, email, a webhook, or a human approval step.
Cost and FinOps, per agent.
Token usage and spend, rolled up per agent, per model, per provider. A single runaway agent or an expensive model choice shows up in the roll-up before it lands on the invoice.
Security posture, the leadership view.
Agents protected, decisions enforced versus only observed, sanctioning coverage, identity gaps (agents that cannot be cryptographically attributed), and the top risks right now. This is where leadership confirms that growth in AI agents has not outrun the controls around them.
Make the audit a non-event.
Every decision is one identity-attributed entry in a tamper-evident record: the agent’s cryptographic identity, and when it acted on behalf of a person, that person’s identity from your identity provider. Nothing an agent does goes unrecorded, and nothing recorded can be quietly changed.
Identity-attributed
Tamper-evident
Tiered retention
Open export
- agent
- did:compfly:…7f2e
- acting for
- employee identity · from your IdP
- action
- email.send
- decision
- denied · control and reason recorded
- hash
- sha256:9f3a…c1d4
Findings and controls carry the framework labels your compliance teams answer to, so evidence lines up with what auditors ask.
See an audit query answered in seconds.
Pick any agent decision and trace it to the authority behind it, with evidence an examiner can verify.