All Features
Prove · Oversight

Who and what has access

One register of what can reach your systems: your people, the apps your team built, the AI tools on their machines, and the automations that run without anyone.

Governance and Audit
Prints to PDF
People
12
reads 9 · writes 4
Apps
7
reads 7 · writes 5
AI tools
19
reads 6 · writes 2
Automations
23
reads 5 · writes 5
Acted without a person
1,847
runs started on their own
312
writes to outside systems
3
apps reaching outside your workspace
Exposure
Writes to outside systems measured
5 apps
Reaches outside your workspace measured
3 apps
Can return content written outside your company declared
18 services
Audit record goes back
Age of your oldest record, not a retention setting
96 days
EU AI Act Article 26 floor: 183

What Oversight gives you

Who And What Has Access

People, apps, the AI tools on their machines, and the automations inside those apps, listed together. Most access reviews cover the first one and stop.

Acted Without A Person

Runs that started on their own, writes that went to outside systems, and apps that reached outside your workspace. This is the part a security review asks about first.

Who Can Reach What

A map from each actor to each system it touches, with read and write counts on every connection. Reads show what it can see, writes show what it can change.

Rules In Force

Which model is pinned, which commands are blocked and which are allowed, which skills and MCP servers get sent to each machine, and how much of the team is actually in sync.

Roles And Keys

Every role and every API key, with what it can reach. Keys outlive the person who made them, which is why they are on the same page as the people.

Models Doing Your Work

Which models ran your team's work, and a warning when one of them is a preview model. Preview models can change without notice, so it matters that you know.

How Far Back The Record Goes

The length of your audit record in days, set against the six-month regulatory floor. A young workspace reads short because it is young.

A Report Built To Forward

The Governance and Audit report prints to PDF. No AI computes any figure in it; every line comes from the audit log, so it prints the same twice.

Access from anywhere

Claude ChatGPT Cursor

AI Agents

Ask your AI agent:

Connect your AI agent

Desktop & Web

Runwork Desktop
Your AI Tools 13 detected
Codex DEFAULT
Claude Code
Cursor
+10 more
Your Team's Skills 39 shared
press-release-lead-monitor
dtp-demand-tracker
Your Integrations 18 connected
HubSpot Sheets lemlist +15

The Governance and Audit report lists what has access, what acted without a person, the reach map, rules, roles and keys, models used, and how far back your record goes. It prints to PDF.

Why Oversight matters

How Oversight works

Access reviews usually cover people. Your team's AI work is done by more than people: apps your agents made, the AI tools installed on everyone's machines, and automations that run inside those apps on their own. This page puts all four in one register, because a review that only counts employees misses most of what can reach your systems.

The panel worth opening first is the work that acted without a person. Runs that started on their own, writes that landed in outside systems, and apps that reached outside your workspace. Automation is the point of the product, so the honest thing is to count it plainly and show what it touched rather than let it sit unlabelled.

From there you can follow any actor to the systems it reaches, with read and write counts on each connection. Reads tell you what something can see. Writes tell you what it can change, which is usually the more important number.

Some of this is measured and some of it is declared, and the page says which is which. Whether a connected service can return text that somebody outside your company wrote is a declared property of the services we list, not something we detect: no call record can say who authored the bytes it returned. Marking that as declared rather than measured is the difference between a document a reviewer trusts and one they stop reading.

The same applies to the record itself. The page shows how many days your audit record runs and compares that with the 183-day floor in Article 26 of the EU AI Act. That number is the age of your oldest record, so a workspace opened last month reads short for reasons that have nothing to do with how it is governed.

All of it prints to a PDF you can forward. No AI computes any figure in the report. Every line derives from the audit log and your workspace registries, which is what makes it the same document tomorrow. When a security review asks how your team's AI work is governed, this is the document that answers it: the audit log is the record, and this is the report built on top of it.

Frequently Asked Questions

What counts as something with access?
Four things: the people in your workspace, the apps your team built, the AI tools connected from their machines, and the automations that run inside those apps. All four can reach data and outside systems, so all four are in the register.
What does "acted without a person" mean?
Work that ran with nobody starting it: scheduled runs, automations, and agent tasks. The panel counts those runs, the writes that went to outside systems, and the apps that reached outside your workspace.
Is everything on this page measured?
No, and the page says which is which. Whether a connected service can return content written by someone outside your company is a declared property of the services listed, not a measurement. No call record can tell us who authored the content it returned, so we do not claim to detect it.
What does the 183-day comparison mean?
Article 26 of the EU AI Act sets a six-month floor for keeping automatically generated logs. The page shows how far back your audit record actually goes and compares it with that floor. It is the age of your oldest record rather than a retention setting, so a new workspace reads short simply because it is new.
Can I send this to a security reviewer?
That is what it is for. The Governance and Audit report prints to PDF like the other reports, and no AI computes any figure in it, so the numbers a reviewer checks today are the numbers they see when they open it again.

Use Cases

Answering a security review Checking what runs without a person Reviewing who and what has access Finding keys nobody owns any more Seeing which models did your work Showing an auditor how far back the record goes

Related Features

See How Teams Use Oversight

Ready to try Oversight?

One shared cloud under the AI tools your team already uses.