Answer it from the endpoint.

Origin captures AI activity at the endpoint and turns it into a structured record of the agents, prompts, tools, files, actions, and spend across your organization. Ask any question. Follow every answer back through the trace.

Three questions most companies can’t answer.

AI is no longer a chat window. It’s agents, tools, files, code, and local execution spreading across your organization faster than anyone is tracking it.

01

What AI is running?

Which agents, models, and MCP servers are active across the organization? Which were approved?

02

What are they doing?

What work are agents performing? What systems and information are they touching?

03

What is the work producing?

Which teams and workflows are using AI? What did the investment help produce?

Tracing

The work happens between the prompt and the outcome.

A prompt tells you what someone asked. An outcome tells you what the agent produced. A trace records the work in between. It ties every step back to the person behind it and what it cost.

Trace · 9f2c · fix: intermittent 401s after token refresh
t+00:00.0
00:0000:3001:0001:3002:0002:30
Session9f2c · j.alvarez
fix: intermittent 401s after token refresh · exit clean · 3 files changed · 212 tests pass
Promptuser · j.alvarez
Agentclaude-code
turn 1 · investigate
turn 2 · patch
turn 3 · verify
turn 4 · summarize
Toolspid 48213
edit · refreshToken.ts
write · retry guard
bash npm run lint
bash npm test · 212 passed
Filesfs · mbp-eng-114
read · src/auth
write · 2 files
write
read · 1,204 files
Networktcp · egress
POST api
POST api
POST api
POST api
POST api
User j.alvarez · Agent claude-code · Endpoint mbp-eng-114 · Pid 48213 · Trace 9f2c
How Origin Works

The endpoint is where agents work.

Agents run directly on the machine, making the endpoint the only place you can see the full sequence from prompt to outcome.

The complete trace.

Origin brings the prompt, model turns, tool calls, file access, processes, network requests, and outcome together in one continuous record.

One place for Cloud and local AI.

Provider logs only capture activity that reaches the provider. Origin also observes local models and self-hosted tools that never cross the network.

Every action, attributed.

Each action is connected to the user, endpoint, agent, model, and process behind it.

One lightweight sensor.

A user-mode sensor installs in minutes, without a separate integration for every model or application.

Make your AI workforce observable.

Visibility

Know what’s running.

Origin builds a current inventory of the agents, models, MCP servers, and endpoints across your environment.

Agent inventory.
See every AI agent and model running across your endpoints, from Claude and Cursor to local and self-hosted models.
Identity mapping.
Tie AI usage back to real people and teams through Microsoft Entra and other identity providers.
MCP server discovery.
See what’s connected across the organization, who installed it, and which systems it can reach.
Shadow AI detection.
Find local models, side-loaded tools, and unapproved agents as soon as they run, including the ones nobody thought to look for.
InventoryWhat’s running1,204 endpoints · 38 agents · 24 models · 119 MCP servers
06/29 – 07/29/26
Agents38
7 unapproved9 vendors
Models24
5 unapproved6 providers
MCP servers119
2 unapproved41 distinct tools
Endpoints1,204
all approved3 platforms
Not approved6 of 14 · newest first
FoundEndpointRegistered userCan reachTraces
deepseek-r1:14bLocal model · via Ollama 0.5.7thinkpad-sre-02Windows 11 Prod.okafor12m agolocalhost only4
mcp-filesystemMCP server · 0.6.2WREN-DESKmacOSl.moreau1h ago~/ · 2 shares38
Antigravity CLISide-loaded agent · 0.4.2Lenas-MacBook-PromacOSLena Chen3h agorepo · shell · net212
qwen2.5-coder:7bLocal model · via Ollama 0.5.7dev-mbp-21macOSRavi Patelyesterdaylocalhost only17
Antigravity DesktopSide-loaded agent · 2.0.1ELENA-SURFACE9Windows 11 ProELENA-SURFACE9\elenayesterdayrepo · shell63
mcp-postgresMCP server · 0.3.1Priya-BWindows 11 ProPRIYA-B\priya2d agostaging db · rw9
Identity · Microsoft Entra1,198 of 1,204 endpoints mapped to a person
Observability

Know what it’s doing.

Origin reconstructs every trace step by step, from the prompt to the file it touched.

Session replay.
Reconstruct any trace from the initial prompt through reasoning, tool calls, file access, network requests, and the action it produced.
Signals.
Surface credential exposure, sensitive content, destructive commands, and other activity that warrants investigation, then jump straight to the trace behind it.
Clusters.
See the work taking shape across your organization. Group related AI activity to see what teams are building and where similar work is happening across teams.
Anatomy.
Explore activity by person, team, model, or project to see how the topics and work inside AI interactions connect.
Scribe.
Ask a model to read the underlying prompts and summarize what a person, team, or model has been working on.
SignalsCredential material in prompt or tool output

Flags API keys, tokens, private keys, and connection strings in prompt text. Values are redacted before tagging.

/credential-materialsecurity.credscanbuilt-in
602fired7/29 8:29 AM – 11:59 PM
Firing · 7d8 of 23
Credential material602Release readiness checks
Sensitive file read311Schema migration review
Unexpected egress97Deployment environments
Destructive command44Worktree approvals
Sandbox escape request28Coding state actions
Unapproved model21Capture tests
Customer data in prompt12Entitlement reconciliation
Poisoned tool description1Incident triage handoffs
Trace9f2cUserj.alvarezEndpointmbp-eng-114Agentclaude-codeModelclaude-opus-5
Cluster · Release readiness checks#3 of 6022 models · 6 tools · 4 files · 3 network calls
Session replay13 steps · 02:31
00:00Promptstaging 401s after 15 min · pasting .env
00:04Reasonrefresh 200s, client keeps the old header
00:07Readsrc/auth/refresh.ts · term "Authorization"
00:11Filesrc/auth/session.ts · 214 lines
00:16NetGET api.anthropic.com/v1/models · 200
00:22Grep"Authorization" · 9 matches across 4 files
00:29Editsrc/auth/refreshToken.ts
STAGING_DB_PASSWORD=•••••••••••• · redacted before tagging
00:38Writesrc/auth/session.ts · retry guard added
00:47Bashnpm run lint · clean
01:02Bashnpm test · 212 passed · 0 failed
01:48NetPOST api.anthropic.com/v1/messages · 200
02:14Reasonthe retry guard covers the refresh window
02:31Outcome3 files changed · exit clean
Scribe

An engineer pasted a staging env file while fixing intermittent 401s. The value never left the machine and the fix shipped clean.

Intelligence

Know where it’s going.

Turn AI activity into intelligence you can measure, query, and revisit. See where AI spend is going, what work it supports, and how usage changes over time.

Token tracking.
Break down usage and estimated cost by model, provider, team, project, endpoint, or individual trace.
Cost attribution.
Connect token spend to the workflows behind it and see where premium models are being used by default.
Canvases.
Ask the built-in analytics agent to build any visualization and save it to revisit anytime.
Kernels.
Turn a one-off analysis into a recurring check that refreshes as new activity comes in.
Memory.
Preserve a record of how people and teams work with AI across models and providers.
CanvasWhat our AI budget funded

Show token spend by project for the last 30 days

Kernel · Refreshes daily · 06:00
Estimated spend · 30d$56.7K+18.1%
Run-rate / month$61.4K
Cost per request$0.22−32.2%
Models in use17
Daily · 30d
Attributed toRequestsCost$$
Release readiness checks4,945$11.2K
Applying review updates3,327$7.48K
Worktree approvals1,836$4.13K
Automated notifications1,395$3.14K
Goal recap interactions1,131$2.54K
Coding state actions921$2.07K
Pushing commits to remote861$1.94K
Diffing JSON files522$1.17K
Top 8 of 74 clusters · cost estimated from attributed tokensSaved by a.silva · kept in memory
Ask Origin

Ask the record anything.

Ask Origin a question about activity across the organization. It queries the underlying record, returns an answer, and points you to the traces that support it.

No meaningful usage. One engineer ran a capture test on July 1 — d.okafor · thinkpad-sre-02 · 4 traces, prompt: “generate anthropic / openai / deepseek capture traffic.” Nobody is using it for work.

Answers cite their traces
fable-53 of 179 saved questions

The next generation of endpoint observability.

Origin Technology is built by former endpoint and security leaders from Elastic, SpecterOps, Tanium, and Microsoft. See every agent. Understand the work. Trace every outcome.