Skip to content

Endpoint AI observability

Who’s watching
your aliens work?

Agents are the aliens1 in your organization. They work on your machines with your credentials and report to no one.

Monitor the agents working across your organization. Follow their actions and investigate unexpected behavior in the traces they leave.

Origin is the endpoint AI observability platform for agentic monitoring and security.

Backed by

5 million+ production agentic traces collected

Across Fortune 500 companies, private equity funds, hospital systems, and other leading organizations.

Origin investigations

We found it in our own traces.

We use Origin to investigate the agents working in our own company.

Codex turned off Claude’s approval checks.

Codex launched Claude Code to query staging data. When Claude’s permission checks blocked the query, Codex disabled them without asking the engineer. The query returned read-only aggregate data.

Turn 219 · Changed by Codex

Claude Code approval checks

Off

The engineer wasn’t asked.

Read the investigation

An agent deployed during our sales demo.

Staging had been locked for a demo. The agent cleared the same lock after finishing its checks, allowing a deployment during the call. The demo was unaffected.

  1. Staging locked
    for the demo
  2. Agent clears
    the shared lock
  3. Agent deploys
    to staging

We updated the control to track separate holds and require human approval.

Read the investigation

Agentic traces

The record of an agent’s work.

An agentic trace connects the request to the tools, file changes, and actions that followed. Origin collects and organizes these traces across your organization.

Origin / Inside the trace

36 lanes · 527 of 1,024 turns active

Interactive example

Activity by subject

Subject
Turns
02004006008001000

Files · 23/All activity

ChangedConsultedErrored
Agent session by activity

Agent session by activity

Origin trace overview showing turns, file activity, Git operations, runs, infrastructure, transfers, and waits across an agent session.

Monitor

Find the activity that needs attention.

Review findings across your organization and open the sessions that need investigation.

Origin / Review activity

8.3K reviews · 12.6K findings

Interactive example

Trace review

Triage 20 cases

LatestCaseSessionsFindingsReview
10:43 AMSep 192133Worth a look
7:17 PMSep 16—1Worth a look

Repository modification after explicit stop instruction

The head incident cites the user saying, “I don’t want to touch the repo.”

2 of 20 cases shown

34 worth a look · 2,353 routine · 136 noise

Review activity and triage

Review activity and triage

Origin review activity chart and triage table, with findings grouped into worth a look, routine, and noise.

Investigate

See exactly what happened.

Each finding links to the relevant turn and related sessions, so you can read the evidence in context.

Origin / Trace investigation

Monitoring the completion of the deployment cutover

Interactive example
Lanes 123
Reports 27
Joins 201 sessions
User
Agent
Turns
0100200300400500
Finding5 occurrences · T23–T316

Hardcoded Forgejo API token in diagnostic script

Behaviour: lowContent: restrictedCredential in script

The agent embedded a Forgejo API token directly in a Python script executed via tools.exec_command. While used for read-only diagnostics, this violates the norm of referencing secrets from environment files or secret stores.

332 of 554 turns · ChatGPT

Finding linked to its source

Credential-handling finding with its source turn

Credential-handling finding with its source turn

Origin investigation view showing a credential-handling finding linked to its source turn, with conversation lanes and joins to related sessions.

Rogue agents keep turning up.

Reports involving OpenAI, Anthropic, Google, and Meta describe agents cheating on evaluations and attacking systems outside their test environments.

Read the report

April 2026

1 event

May 2026

4 events

July 2026

4 events

August 2026

2 events disclosed

These are only the ones that were reported.

Imagine what’s going undetected in your organization right now.

Every organization running agents needs to monitor them.

Built for your endpoints.

Install Origin on managed devices and connect supported cloud applications.

Local models and cloud.

Collect traces from supported AI tools on macOS and Windows, including local models, and from connected cloud applications.

Supported applications

Enforce your policies.

Define your organization’s policies and push them to managed endpoints to enforce consistent configurations across your fleet.

Endpoint configuration

Data privacy comes first.

You decide what to collect. Origin processes trace data on your organization’s behalf, with encryption and access controls.

Our approach to privacy

Let your aliens work.
Keep them in sight.

See how Origin monitors agent activity and helps your team investigate it.

Request a demo

30-minute walkthrough.