Skip to main content

Swif AI Agent Activity Monitoring Policy

Overview

The Swif AI Agent Activity Monitoring Policy records the sessions and tool activity of AI coding agents on managed macOS, Windows, and Linux devices, so admins can review what each agent did.

The sensor reads the local logs that supported AI agents write, converts the activity into a common format, and uploads it to Swif. Use it to:

  • see which AI agents, models, and tools are used on your devices

  • review prompts, responses, and tool calls for a session

  • investigate suspicious commands, prompt injection, unauthorized file access, or possible data exfiltration

  • optionally have Swif analyze sessions for risky behavior

Important: This policy collects sensitive data. Session records can include prompts, responses, project paths, tool arguments and results, usernames, and hostnames. Review Privacy and security considerations below and inform affected users before you turn it on.

This policy monitors only. It doesn't block anything. To block destructive commands, use the Swif AI Agent Command Protection Policy.

Requirements

Requirement

Details

Operating systems

macOS, Windows, and Linux

Device ownership

Company-owned and BYOD

Agent

Swif Agentic Security installed and running. Version 1.28.0 or later is recommended for collection intervals under 20 minutes. Deploy it with the Apple, Windows, or Linux Agentic Security Policy.

Local data

At least one supported AI agent must have local session data on the device

Connectivity

The device must be online to receive the policy and upload data

How it works

  1. A supported AI agent writes session, conversation, or tool-use data to its local storage.

  2. On the schedule you set, the Swif agent runs the sensor, which reads that data.

  3. The sensor converts the activity into session records, covering the number of days you choose.

  4. If Upload Enabled is on, the records are uploaded to Swif.

  5. If Risk Detection Enabled is on, Swif analyzes the uploaded sessions for risky behavior.

  6. You review sessions in Agentic Security > Devices > [device] > Activity > AI Agent Sessions.


Settings reference

Setting

What it does

Default

Range

Enabled

Turns activity collection on or off. While it's off, nothing is collected or uploaded.

Off

—

Monitored Agents

The AI agents to monitor. Leave empty to monitor all supported agents.

Empty (all)

See below

History Window (Days)

How many days of session history to include in each upload.

14

1–30

Collection Interval (Minutes)

How often the device collects AI agent activity.

15

5–1,440

Upload Enabled

Uploads collected activity to Swif. When off, records stay on the device.

On

—

Risk Detection Enabled

Analyzes uploaded sessions for risky behavior. Requires Upload Enabled. Sends session data to an approved external LLM provider.

Off

—

If you turn on Enabled and keep the other defaults, the device collects from all supported agents every 15 minutes, includes up to 14 days of history, and uploads it to Swif. Risk detection stays off.

Monitored agents

Value

AI agent

macOS

Windows

Linux

Local data read

claude

Claude Code

✅

✅

✅

JSONL session files

codex

OpenAI Codex CLI

✅

✅

✅

JSONL session files

claude_desktop

Claude Desktop local agent mode, including Claude Cowork

✅

✅

—

Local audit JSONL files

cline

Cline

✅

✅

✅

Local JSON task files

cursor

Cursor

✅

✅

✅

Local SQLite app state

warp

Warp Terminal

✅

✅

—

Local SQLite app data

Agents that aren't available on a device's operating system are skipped.

Leaving Monitored Agents empty collects from every supported agent. It also includes opencode, which isn't available as a separate option. To limit collection, list only the agents your organization has approved.

Choosing the history window and interval

  • History Window (Days): a shorter window means less data and less privacy exposure. A longer window gives more context for investigations. It doesn't delete data already uploaded to Swif. Apply your own retention rules to that data.

  • Collection Interval (Minutes): a shorter interval shows sessions in Swif sooner, but uses more processing and network. The 15-minute default suits most organizations. Use 5 minutes only for an active investigation.

Collection timing depends on the agent version:

Agent version

How the interval works

1.28.0 and later (macOS, Windows, Linux)

Collection runs on its own schedule, checked every minute. Intervals from 5 to 15 minutes take effect as set.

1.27.0 and earlier

Collection runs with the agent's 20-minute policy check. Any interval under 20 minutes effectively runs every 20 minutes.

On any version, a policy change can take up to 20 minutes to reach the device.


Data collected

What's collected depends on the AI agent, its version, and what it records locally. It can include:

Category

Examples

Device and user

Hostname and local username

Session

Session ID, timestamp, and agent

Model

Model name recorded by the agent

Project

Local project or workspace path

Conversation

User prompts and assistant responses

Tool activity

Tool name, type, arguments, results, and status

Agent configuration

Available tools, MCP servers, plugins, skills, or permission mode, where the agent records them

The sensor only reads what the agent already logged. It can't collect activity the agent didn't record, or sessions the agent or user has deleted.


Risk detection

When Risk Detection Enabled is on, Swif analyzes each uploaded session for:

  • Credential theft and access: attempts to read local credentials, environment secrets, or unauthorized folders

  • Prompt injection: malicious instructions in code, issues, or web content that steer the agent

  • Data exfiltration: unapproved transfer of code or sensitive data through tool calls

  • Destructive operations: high-risk shell commands, system changes, or attempts to evade security controls

Each analyzed session gets a finding:

Field

Values

Verdict

Malicious, Benign, or Unknown

Analysis State

Complete, Partial, or Failed

Summary and reasoning

A short explanation of why the session was flagged

Risk detection sends full sessions to an external AI provider. To score a session, Swif sends the full session, including prompts, responses, and tool inputs and outputs, to an approved external LLM provider. Analysis runs on Swif's servers, never on the device. Findings contain only the verdict, summary, and reasons, not transcripts or tool output, and paths and secrets are redacted from the summary.


Before you start

  1. Complete a privacy and security review, including whether risk detection's use of an external LLM provider is acceptable.

  2. Inform affected users that AI agent session data will be collected.

  3. Decide which AI agents to monitor. List only approved agents.

  4. Choose a pilot group of company-owned devices that covers each operating system in your fleet.

  5. Decide on BYOD. Don't reuse your company-owned configuration on BYOD devices without a defined business scope, employee notice, and an approved data-handling process.


Create the policy

  1. In Swif, go to Agentic Security > Policies.

  2. Select Swif AI Agent Activity Monitoring Policy.

  3. Enter a name, such as AI Activity Monitoring – Pilot.

  4. Turn on Enabled.

  5. Under Monitored Agents, select the approved AI agents.

  6. Set History Window (Days) and Collection Interval (Minutes).

  7. Turn Upload Enabled and Risk Detection Enabled on or off.

  8. Assign the policy to your pilot devices and save.

Expand to more devices after the pilot and your privacy, security, and legal reviews are complete.


Example configurations

Example 1: Pilot on company-owned devices

Setting

Value

Enabled

On

Monitored Agents

claude, codex, cursor

History Window (Days)

7

Collection Interval (Minutes)

15

Upload Enabled

On

Risk Detection Enabled

On, after privacy review

An explicit agent list and a 7-day window keep collection small, while giving enough recent activity to validate the policy.

Example 2: Check locally before uploading

Setting

Value

Enabled

On

Monitored Agents

codex

History Window (Days)

1

Upload Enabled

Off

Risk Detection Enabled

Off

Activity is collected but stays on the device. Use this during a technical or privacy evaluation. Sessions won't appear in Swif until you turn on upload.

Example 3: Active investigation

Setting

Value

Enabled

On

Monitored Agents

claude, claude_desktop, cursor

History Window (Days)

30

Collection Interval (Minutes)

5

Upload Enabled

On

Risk Detection Enabled

On

Collect the most history as often as possible. Return to the default interval and a shorter window when the investigation ends.


Verify the policy

Use a test session that contains no credentials, customer data, or proprietary code.

  1. Confirm that the device is online and the policy shows as applied.

  2. Run a short session in one of the monitored AI agents.

  3. Wait for the policy to reach the device (up to 20 minutes), then for the collection interval to pass (15 minutes by default).

  4. Go to Agentic Security > Devices, select the device, and open Activity > AI Agent Sessions.

  5. Confirm that the session appears with the expected agent, model, project path, and time.

  6. Open the session and check the Chat History and Tool Usage tabs.

  7. Confirm that agents not in Monitored Agents don't appear in new sessions.


View AI agent sessions

  1. In Swif, go to Agentic Security > Devices.

  2. Select the device.

  3. Open the Activity tab, then AI Agent Sessions.

Search and filter

Filter

What it does

Search

Matches session ID, username, project path, model, or agent. Partial text works, such as sonnet or sample-repo.

Source

Filters by AI agent: claude, codex, cursor, cline, claude_desktop, or warp

Time range

Shows sessions that started between a start and end time

If the policy is active but no sessions have been collected yet, the list is empty.

Session details

Click a session to open its details.

Chat History (shown first) lists the messages between the user and the AI agent, labeled User and Assistant.

Tool Usage lists the tools, commands, arguments, times, and results from the session.

Each tab can show:

State

Meaning

Empty

The agent supports this data, but none was recorded in the session.

Unsupported

The agent doesn't record this kind of data.

Partial data (Tool Usage)

Some tool calls weren't fully captured in the agent's logs, as can happen with Codex CLI.


Privacy and security considerations

  • Tell affected users that AI agent session data may be collected.

  • Document the business purpose and legal basis for collection.

  • Check whether prompts, responses, tool results, or paths could contain secrets, personal data, customer data, or proprietary code.

  • List only approved agents in Monitored Agents.

  • Use the shortest History Window (Days) that meets your needs.

  • Limit who in your organization can view uploaded sessions in Swif.

  • Set retention and deletion rules for uploaded data.

  • Test BYOD devices separately from company-owned devices.

  • Review risk detection's use of an external LLM provider before turning it on.

The policy doesn't change the AI agents' own logging or privacy settings. Review each agent's storage, cloud processing, and retention separately.

The ADR Sensor is open source under the Apache License 2.0. Review its source code and release history as part of your software supply-chain process.


Change or turn off the policy

  • To change collection: edit the policy, save it, and let devices check in. A change can take up to 20 minutes to reach a device. The next collection after that uses the new settings.

  • To stop collection: turn off Enabled or unassign the policy. No new data is collected after devices check in.

Turning off the policy doesn't delete:

  • the AI agents' own session logs

  • records already created on the device

  • sessions already uploaded to Swif

  • data forwarded to other systems

Follow your retention and deletion procedures for each location.


Troubleshooting

The policy is applied, but no sessions appear

  • Check that Enabled and Upload Enabled are on.

  • Check that the device is online and the Swif agent is running.

  • Check that a monitored AI agent has recent local session data.

  • Check that the session falls within History Window (Days).

  • Wait for Collection Interval (Minutes) to pass, then refresh.

Only some AI agents appear

  • Check that the missing agent is in Monitored Agents, or that the list is empty.

  • Check that the agent is supported on the device's operating system. Claude Desktop and Warp aren't supported on Linux.

  • Check that the agent has created local session data.

Older sessions are missing

Increase History Window (Days), up to 30. Also check that the AI agent still has the session locally. The sensor can't collect a session after its records are deleted.

Sessions are collected but don't appear in Swif

  • Check that Upload Enabled is on.

  • Check that the device is online and can reach Swif.

  • Check that you're viewing the correct device and time range.

If the device was offline, wait for it to reconnect and complete another collection.

Sessions arrive every 20 minutes, even with a shorter interval

The device runs Swif agent 1.27.0 or earlier, where intervals under 20 minutes effectively run every 20 minutes. Update the agent to 1.28.0 or later.

Collection uses more resources than expected

  • Increase Collection Interval (Minutes).

  • Reduce History Window (Days).

  • List only the agents you need in Monitored Agents.

Sessions don't have a risk verdict

  • Check that Risk Detection Enabled and Upload Enabled are both on.

  • Check the session's Analysis State. Partial or Failed means the analysis didn't complete.


Related resources

Swif

Did this answer your question?