AgentSight is a plan feature and requires its own agent installed on the
hosts running your AI workloads. Talk to your account contact about
enabling it.
What it shows
Why kernel-level
An agent’s own logs describe what it believes it did. Kernel observation
records what actually happened at the system boundary — the process that was
spawned, the connection that was opened, the file that was read.For a component whose whole purpose is taking autonomous action, the
difference between those two is the entire point of monitoring it.
Governance alerting
Alert rules of type governance evaluate policy conditions against AgentSight data — so “an agent did something outside what we permit” becomes a notification rather than something discovered later. Governance rules run on the ordinary 60-second alerting loop. See Alerting.Retention
Raw events are kept for 30 days; rolled-up aggregates for 90 days. Same shape as the rest of the platform — recent detail, longer-lived trends.What it is not
Next
LLM observability
Cost, latency and errors for your model calls.
Alerting
Governance rules and how the loop evaluates.
Security events
Detections, runtime threats and exposed secrets.