Update cookies preferences
AI Observability

See everything. Enable everyone.

Discover every AI asset in your environment, capture every prompt and tool call inline, and attribute activity to the users and systems behind it.

Get a demo
Illustration of a planet resembling Saturn with textured yarn-like swirling patterns in blue and purple and a yellow knitted ring around it.
Securing AI by the world's top providers

The Onyx Approach

AI assets show up in your environment faster than your legacy and static inventory tools can keep up. Agents, MCP servers, copilots, and embedded AI surfaces are being adopted outside of your control. Configurations drift, sessions cross identity boundaries, and by the time static catalog vendors push an update, three more AI features have shipped inside your existing SaaS tools.

Your security and compliance teams need asset information, session activity, identity chain, exposure radius, and risk in one place, with coverage that keeps pace with the sprawl. Onyx is the platform that delivers continuous, automated discovery and risk scoring.

Starship model crafted entirely from knitted yarn in blue, purple, and gold colors.

The Onyx Difference

Table listing AI apps with risk scores, types, and sessions, highlighting Deepseek with highest risk score 8.7.

Continuous AI Asset Discovery

Onyx identifies every agent, MCP server, AI tool, copilot, and embedded AI surface in your environment continuously, across SaaS, cloud, endpoints, and code. Static catalogs can't keep up with how fast AI features ship inside your existing SaaS tools. Onyx combines directory scanning, native platform APIs, and behavioral signature learning for browser-based AI to keep the inventory current, and each record carries the configuration that drives behavior: skills, tools, memory, model, owner, and lifecycle stage.

Bar chart showing sessions over time with 1,231 sessions and a 1.3% increase, plus Onyx Guardian note.

Session Capture and Reasoning Context

Every prompt, model response, and tool call is recorded by name, argument, and result, with the reasoning context preserved across turns. Investigators get the full story of what an agent did and why in one record, instead of stitching together logs from three separate tools.

Alert for sensitive data violation showing a blocked PIN detected by Onyx Guardian agent.

Identity-Aware Activity Attribution

Onyx correlates agent activity to the invoking user and the agent owner, and captures the identity used on each tool and MCP call. Investigators trace an agent action back to the person and systems behind it, without stitching credentials across tools.

See Onyx Connect to Your Stack

Onyx drops in next to the identity, cloud, network, and endpoint tools your team already runs. Most environments produce a working AI inventory within 24 hours and an enforced governance policy on day one. To see real-time AI security across your stack...

schedule a demo

Connects to the Tools You Already Run

Onyx enriches AI asset inventory and identity with context from the platforms your organization already runs, reducing the timeline for identification and policy configuration.

  • Every agent, MCP server, and copilot arrives with its full configuration attached, along with the owner, permissions, and lifecycle stage.
  • Identity, endpoint management, and agent-building platforms already in your environment feed Onyx with the context to attribute each action to a real user and a real system.
  • Alerts and session records synchronize with your SIEM with the reasoning trace and tool call history preserved, so an incident review starts with the facts already in hand.
Illustration of a planet resembling Saturn with textured yarn-like swirling patterns in blue and purple and a yellow knitted ring around it.

Frequently Asked Questions

What is Onyx AI Observability?

The discovery and runtime visibility layer of the Onyx Secure AI Control Plane. Onyx maintains a live inventory of every AI asset, captures session activity at step-level granularity, and attributes every action to the users and systems behind it.

What does Onyx capture at the session level?

Every prompt, every model response, and every tool call by name, argument, and result, with reasoning context preserved across turns. The session is the unit of investigation.

How does identity attribution work?

Every record ties to the invoking user, the agent owner, and the identity in use on each tool call and MCP call. Investigators can trace an agent action across the identities involved without leaving Onyx.

How does Onyx feed downstream tools?

Alerts and their session records forward to Splunk and CrowdStrike NG-SIEM. The SIEM is the primary downstream destination today.