APIAnalytics

Tool access summary

Org-wide tool-access totals.

GET
/analytics/tool-access/summary

Org-wide tool-access totals.

Authorization

ApiKeyAuth
headerAuthorizationBearer <token>

Bearer token authentication. Send an API key (a saai_api_-prefixed token) as Authorization: Bearer <token>.

Required permission

view_user_analytics

Query Parameters

start_time*string

Start of the time range to report on, inclusive.

Formatdate-time
end_time*string

End of the time range to report on, exclusive.

Formatdate-time
exclude_local?boolean

Leave out client built-in (local) calls.

Response Body

The request has succeeded.

application/json
  1. response

Org-wide tool-access totals for a time range, from agent telemetry. Calls without a user email count in these totals and the hourly breakdown, but not in identities or the severity matrix.

identities*integer

Distinct identities (user emails) whose agents called a tool.

Formatint64
regulated_identities*integer

Identities with at least one call on a regulated system.

Formatint64
events*integer

Log records and spans the org sent in the range, across all telemetry, not only tool calls. Unaffected by exclude_local.

Formatint64
calls*integer

Tool calls.

Formatint64
systems*integer

Distinct systems called.

Formatint64
write_systems*integer

Distinct systems called through a write-capable tool.

Formatint64
sensitive_calls*integer

Calls to sensitive tools.

Formatint64
write_calls*integer

Calls to write-capable tools.

Formatint64
unclassified_calls*integer

Calls that matched no classification.

Formatint64
critical_identities*integer

Identities with at least one critical call.

Formatint64
multi_system_write_identities*integer

Identities writing to more than one system.

Formatint64
wide_write_identities*integer

Identities writing to three or more systems.

Formatint64
write_chain_identities*integer

Identities holding a complete exfil path: a protected read, a change, and a send out.

Formatint64
curl -X GET "https://example.com/analytics/tool-access/summary?start_time=2019-08-24T14%3A15%3A22Z&end_time=2019-08-24T14%3A15%3A22Z"
{  "identities": 0,  "regulated_identities": 0,  "events": 0,  "calls": 0,  "systems": 0,  "write_systems": 0,  "sensitive_calls": 0,  "write_calls": 0,  "unclassified_calls": 0,  "critical_identities": 0,  "multi_system_write_identities": 0,  "wide_write_identities": 0,  "write_chain_identities": 0}