Tool access summary
Org-wide tool-access totals.
Org-wide tool-access totals.
ApiKeyAuthAuthorizationBearer <token>Bearer token authentication. Send an API key (a saai_api_-prefixed token) as Authorization: Bearer <token>.
Required permission
view_user_analyticsstart_time*stringStart of the time range to report on, inclusive.
date-timeend_time*stringEnd of the time range to report on, exclusive.
date-timeexclude_local?booleanLeave out client built-in (local) calls.
The request has succeeded.
application/json- response
Org-wide tool-access totals for a time range, from agent telemetry. Calls without a user email count in these totals and the hourly breakdown, but not in identities or the severity matrix.
identities*integerDistinct identities (user emails) whose agents called a tool.
int64regulated_identities*integerIdentities with at least one call on a regulated system.
int64events*integerLog records and spans the org sent in the range, across all telemetry, not only tool calls. Unaffected by exclude_local.
int64calls*integerTool calls.
int64systems*integerDistinct systems called.
int64write_systems*integerDistinct systems called through a write-capable tool.
int64sensitive_calls*integerCalls to sensitive tools.
int64write_calls*integerCalls to write-capable tools.
int64unclassified_calls*integerCalls that matched no classification.
int64critical_identities*integerIdentities with at least one critical call.
int64multi_system_write_identities*integerIdentities writing to more than one system.
int64wide_write_identities*integerIdentities writing to three or more systems.
int64write_chain_identities*integerIdentities holding a complete exfil path: a protected read, a change, and a send out.
int64curl -X GET "https://example.com/analytics/tool-access/summary?start_time=2019-08-24T14%3A15%3A22Z&end_time=2019-08-24T14%3A15%3A22Z"{ "identities": 0, "regulated_identities": 0, "events": 0, "calls": 0, "systems": 0, "write_systems": 0, "sensitive_calls": 0, "write_calls": 0, "unclassified_calls": 0, "critical_identities": 0, "multi_system_write_identities": 0, "wide_write_identities": 0, "write_chain_identities": 0}