Who and what has access
One register of what can reach your systems: your people, the apps your team built, the AI tools on their machines, and the automations that run without anyone.
What Oversight gives you
Who And What Has Access
People, apps, the AI tools on their machines, and the automations inside those apps, listed together. Most access reviews cover the first one and stop.
Acted Without A Person
Runs that started on their own, writes that went to outside systems, and apps that reached outside your workspace. This is the part a security review asks about first.
Who Can Reach What
A map from each actor to each system it touches, with read and write counts on every connection. Reads show what it can see, writes show what it can change.
Rules In Force
Which model is pinned, which commands are blocked and which are allowed, which skills and MCP servers get sent to each machine, and how much of the team is actually in sync.
Roles And Keys
Every role and every API key, with what it can reach. Keys outlive the person who made them, which is why they are on the same page as the people.
Models Doing Your Work
Which models ran your team's work, and a warning when one of them is a preview model. Preview models can change without notice, so it matters that you know.
How Far Back The Record Goes
The length of your audit record in days, set against the six-month regulatory floor. A young workspace reads short because it is young.
A Report Built To Forward
The Governance and Audit report prints to PDF. No AI computes any figure in it; every line comes from the audit log, so it prints the same twice.
Access from anywhere
Desktop & Web
The Governance and Audit report lists what has access, what acted without a person, the reach map, rules, roles and keys, models used, and how far back your record goes. It prints to PDF.
Why Oversight matters
- Covers people, apps, AI tools and automations in one register
- Separates work that ran without a person from work someone started
- Read and write counts on each connection, so writes are visible
- Says which parts are declared and which are measured
- Prints to a PDF you can send to a reviewer
How Oversight works
Access reviews usually cover people. Your team's AI work is done by more than people: apps your agents made, the AI tools installed on everyone's machines, and automations that run inside those apps on their own. This page puts all four in one register, because a review that only counts employees misses most of what can reach your systems.
The panel worth opening first is the work that acted without a person. Runs that started on their own, writes that landed in outside systems, and apps that reached outside your workspace. Automation is the point of the product, so the honest thing is to count it plainly and show what it touched rather than let it sit unlabelled.
From there you can follow any actor to the systems it reaches, with read and write counts on each connection. Reads tell you what something can see. Writes tell you what it can change, which is usually the more important number.
Some of this is measured and some of it is declared, and the page says which is which. Whether a connected service can return text that somebody outside your company wrote is a declared property of the services we list, not something we detect: no call record can say who authored the bytes it returned. Marking that as declared rather than measured is the difference between a document a reviewer trusts and one they stop reading.
The same applies to the record itself. The page shows how many days your audit record runs and compares that with the 183-day floor in Article 26 of the EU AI Act. That number is the age of your oldest record, so a workspace opened last month reads short for reasons that have nothing to do with how it is governed.
All of it prints to a PDF you can forward. No AI computes any figure in the report. Every line derives from the audit log and your workspace registries, which is what makes it the same document tomorrow. When a security review asks how your team's AI work is governed, this is the document that answers it: the audit log is the record, and this is the report built on top of it.
Frequently Asked Questions
What counts as something with access?
What does "acted without a person" mean?
Is everything on this page measured?
What does the 183-day comparison mean?
Can I send this to a security reviewer?
Use Cases
Related Features
See How Teams Use Oversight
Ready to try Oversight?
One shared cloud under the AI tools your team already uses.