Looking for Prelude Security?

You found the right page. We are now Origin, the endpoint AI observability platform for the agent workforce running today.

Already running Prelude Monitor? Nothing changes for you. Same product. Same team. Same way of getting in touch with us.

Contact us

Whether you’re running Prelude Monitor today or sizing up Origin for the first time, we look forward to hearing from you.

What Origin does

Endpoint AI observability, built for the work agents actually do.

The agents your team deployed write code, touch files, call APIs, and spend budget, often faster than anyone can track by hand.

Origin runs at the endpoint, where the work happens. Nothing upstream sees it the same way.

How it works

Ask Origin.

Find every agent and MCP server across the fleet, approved and unapproved alike.

Ask Origin · DiscoveryWhere are our agents?K
You
Show every AI agent and MCP server across the fleet in the last 7 days. Group by endpoint, owner, and install path.
Routing · fleet discovery
analytics_query· done
1,284 agents · 612 endpoints · 91 shadow installs
Claude Code38%
Cursor31%
MCP servers19%
Browser agents12%
1,284 agents across 612 endpoints. 91 are shadow installs not in MDM. The biggest gap is personal Cursor installs on engineering laptops, followed by local MCP servers connected to GitHub.
Ask Origin · DiscoveryWhich endpoints run unsanctioned MCP servers?K
You
Which endpoints are running local MCP servers that aren't in the sanctioned catalog?
mcp_inventory· 47 matches
personal_install ∧ ¬in(sanctioned_catalog)
ENG-MBP-22github-mcp · supabase-mcp
LAPTOP-R180TR52postgres-mcp
ENG-MBP-14slack-mcp · linear-mcp
ENG-MBP-08github-mcp · custom-rag
47 endpoints running 21 distinct MCP servers outside the catalog. Most-touched targets: GitHub, internal Postgres, Slack. None hit the secrets vault — yet.
Ask Origin · DiscoveryWho installed an agent this week?K
You
/audit new agents this week — who, what, where, and is it sanctioned?
Routing · audit · 7d
audit· 214 events
first_observed_within(7d) ∩ kind=agent_install
diego.alvarezCodex · ENG-MBP-22 · personal
kevin.wrightCursor 3.3.30 · MBP-KW · sanctioned
ben.taylorClaude Code · HR-LAPTOP-04 · sanctioned
priya.shahCopilot · FINANCE-PC-07 · sanctioned
214 first-time agent installs this week. 18 are personal / unsanctioned. 196 came through the standard install path; the rest were sideloaded.
Ask Origin · DiscoveryShow agent density by team.K
You
Break down agent installs by team — which orgs are highest density?
analytics_query· done
agents_per_endpoint by org
Engineering64%
Customer Eng48%
Product31%
Security22%
Engineering averages 4.7 agents per laptop — highest density in the company. Customer Engineering is second at 3.2. Marketing and Sales sit below 1.
Ask Origin · DiscoveryPersonal-GitHub connections?K
You
Any agents on the fleet connecting to GitHub from personal accounts?
Routing · attribution
session_trace· 9 sessions
agent.git_auth ≠ user.sso_email
Cursor · ENG-MBP-22auth: diego.gh ≠ diego.alvarez@
Claude · ENG-MBP-08auth: a-singh-dev ≠ aaron.singh@
Copilot · LAPTOP-R180TR52auth: mwong-side ≠ wong.m@
9 active agent ↔ GitHub auth pairs where the agent's commit identity doesn't match the SSO identity. All on Engineering machines.