Overview
The Swif AI Agent Activity Monitoring Policy records the sessions and tool activity of AI coding agents on managed macOS, Windows, and Linux devices, so admins can review what each agent did.
The sensor reads the local logs that supported AI agents write, converts the activity into a common format, and uploads it to Swif. Use it to:
see which AI agents, models, and tools are used on your devices
review prompts, responses, and tool calls for a session
investigate suspicious commands, prompt injection, unauthorized file access, or possible data exfiltration
optionally have Swif analyze sessions for risky behavior
Important: This policy collects sensitive data. Session records can include prompts, responses, project paths, tool arguments and results, usernames, and hostnames. Review Privacy and security considerations below and inform affected users before you turn it on.
This policy monitors only. It doesn't block anything. To block destructive commands, use the Swif AI Agent Command Protection Policy.
Requirements
Requirement | Details |
Operating systems | macOS, Windows, and Linux |
Device ownership | Company-owned and BYOD |
Agent | Swif Agentic Security installed and running. Version 1.28.0 or later is recommended for collection intervals under 20 minutes. Deploy it with the Apple, Windows, or Linux Agentic Security Policy. |
Local data | At least one supported AI agent must have local session data on the device |
Connectivity | The device must be online to receive the policy and upload data |
How it works
A supported AI agent writes session, conversation, or tool-use data to its local storage.
On the schedule you set, the Swif agent runs the sensor, which reads that data.
The sensor converts the activity into session records, covering the number of days you choose.
If Upload Enabled is on, the records are uploaded to Swif.
If Risk Detection Enabled is on, Swif analyzes the uploaded sessions for risky behavior.
You review sessions in Agentic Security > Devices > [device] > Activity > AI Agent Sessions.
Settings reference
Setting | What it does | Default | Range |
Enabled | Turns activity collection on or off. While it's off, nothing is collected or uploaded. | Off | — |
Monitored Agents | The AI agents to monitor. Leave empty to monitor all supported agents. | Empty (all) | See below |
History Window (Days) | How many days of session history to include in each upload. | 14 | 1–30 |
Collection Interval (Minutes) | How often the device collects AI agent activity. | 15 | 5–1,440 |
Upload Enabled | Uploads collected activity to Swif. When off, records stay on the device. | On | — |
Risk Detection Enabled | Analyzes uploaded sessions for risky behavior. Requires Upload Enabled. Sends session data to an approved external LLM provider. | Off | — |
If you turn on Enabled and keep the other defaults, the device collects from all supported agents every 15 minutes, includes up to 14 days of history, and uploads it to Swif. Risk detection stays off.
Monitored agents
Value | AI agent | macOS | Windows | Linux | Local data read |
| Claude Code | ✅ | ✅ | ✅ | JSONL session files |
| OpenAI Codex CLI | ✅ | ✅ | ✅ | JSONL session files |
| Claude Desktop local agent mode, including Claude Cowork | ✅ | ✅ | — | Local audit JSONL files |
| Cline | ✅ | ✅ | ✅ | Local JSON task files |
| Cursor | ✅ | ✅ | ✅ | Local SQLite app state |
| Warp Terminal | ✅ | ✅ | — | Local SQLite app data |
Agents that aren't available on a device's operating system are skipped.
Leaving Monitored Agents empty collects from every supported agent. It also includes opencode, which isn't available as a separate option. To limit collection, list only the agents your organization has approved.
Choosing the history window and interval
History Window (Days): a shorter window means less data and less privacy exposure. A longer window gives more context for investigations. It doesn't delete data already uploaded to Swif. Apply your own retention rules to that data.
Collection Interval (Minutes): a shorter interval shows sessions in Swif sooner, but uses more processing and network. The 15-minute default suits most organizations. Use 5 minutes only for an active investigation.
Collection timing depends on the agent version:
Agent version | How the interval works |
1.28.0 and later (macOS, Windows, Linux) | Collection runs on its own schedule, checked every minute. Intervals from 5 to 15 minutes take effect as set. |
1.27.0 and earlier | Collection runs with the agent's 20-minute policy check. Any interval under 20 minutes effectively runs every 20 minutes. |
On any version, a policy change can take up to 20 minutes to reach the device.
Data collected
What's collected depends on the AI agent, its version, and what it records locally. It can include:
Category | Examples |
Device and user | Hostname and local username |
Session | Session ID, timestamp, and agent |
Model | Model name recorded by the agent |
Project | Local project or workspace path |
Conversation | User prompts and assistant responses |
Tool activity | Tool name, type, arguments, results, and status |
Agent configuration | Available tools, MCP servers, plugins, skills, or permission mode, where the agent records them |
The sensor only reads what the agent already logged. It can't collect activity the agent didn't record, or sessions the agent or user has deleted.
Risk detection
When Risk Detection Enabled is on, Swif analyzes each uploaded session for:
Credential theft and access: attempts to read local credentials, environment secrets, or unauthorized folders
Prompt injection: malicious instructions in code, issues, or web content that steer the agent
Data exfiltration: unapproved transfer of code or sensitive data through tool calls
Destructive operations: high-risk shell commands, system changes, or attempts to evade security controls
Each analyzed session gets a finding:
Field | Values |
Verdict |
|
Analysis State |
|
Summary and reasoning | A short explanation of why the session was flagged |
Risk detection sends full sessions to an external AI provider. To score a session, Swif sends the full session, including prompts, responses, and tool inputs and outputs, to an approved external LLM provider. Analysis runs on Swif's servers, never on the device. Findings contain only the verdict, summary, and reasons, not transcripts or tool output, and paths and secrets are redacted from the summary.
Before you start
Complete a privacy and security review, including whether risk detection's use of an external LLM provider is acceptable.
Inform affected users that AI agent session data will be collected.
Decide which AI agents to monitor. List only approved agents.
Choose a pilot group of company-owned devices that covers each operating system in your fleet.
Decide on BYOD. Don't reuse your company-owned configuration on BYOD devices without a defined business scope, employee notice, and an approved data-handling process.
Create the policy
In Swif, go to Agentic Security > Policies.
Select Swif AI Agent Activity Monitoring Policy.
Enter a name, such as
AI Activity Monitoring – Pilot.Turn on Enabled.
Under Monitored Agents, select the approved AI agents.
Set History Window (Days) and Collection Interval (Minutes).
Turn Upload Enabled and Risk Detection Enabled on or off.
Assign the policy to your pilot devices and save.
Expand to more devices after the pilot and your privacy, security, and legal reviews are complete.
Example configurations
Example 1: Pilot on company-owned devices
Setting | Value |
Enabled | On |
Monitored Agents |
|
History Window (Days) | 7 |
Collection Interval (Minutes) | 15 |
Upload Enabled | On |
Risk Detection Enabled | On, after privacy review |
An explicit agent list and a 7-day window keep collection small, while giving enough recent activity to validate the policy.
Example 2: Check locally before uploading
Setting | Value |
Enabled | On |
Monitored Agents |
|
History Window (Days) | 1 |
Upload Enabled | Off |
Risk Detection Enabled | Off |
Activity is collected but stays on the device. Use this during a technical or privacy evaluation. Sessions won't appear in Swif until you turn on upload.
Example 3: Active investigation
Setting | Value |
Enabled | On |
Monitored Agents |
|
History Window (Days) | 30 |
Collection Interval (Minutes) | 5 |
Upload Enabled | On |
Risk Detection Enabled | On |
Collect the most history as often as possible. Return to the default interval and a shorter window when the investigation ends.
Verify the policy
Use a test session that contains no credentials, customer data, or proprietary code.
Confirm that the device is online and the policy shows as applied.
Run a short session in one of the monitored AI agents.
Wait for the policy to reach the device (up to 20 minutes), then for the collection interval to pass (15 minutes by default).
Go to Agentic Security > Devices, select the device, and open Activity > AI Agent Sessions.
Confirm that the session appears with the expected agent, model, project path, and time.
Open the session and check the Chat History and Tool Usage tabs.
Confirm that agents not in Monitored Agents don't appear in new sessions.
View AI agent sessions
In Swif, go to Agentic Security > Devices.
Select the device.
Open the Activity tab, then AI Agent Sessions.
Search and filter
Filter | What it does |
Search | Matches session ID, username, project path, model, or agent. Partial text works, such as |
Source | Filters by AI agent: |
Time range | Shows sessions that started between a start and end time |
If the policy is active but no sessions have been collected yet, the list is empty.
Session details
Click a session to open its details.
Chat History (shown first) lists the messages between the user and the AI agent, labeled User and Assistant.
Tool Usage lists the tools, commands, arguments, times, and results from the session.
Each tab can show:
State | Meaning |
Empty | The agent supports this data, but none was recorded in the session. |
Unsupported | The agent doesn't record this kind of data. |
Partial data (Tool Usage) | Some tool calls weren't fully captured in the agent's logs, as can happen with Codex CLI. |
Privacy and security considerations
Tell affected users that AI agent session data may be collected.
Document the business purpose and legal basis for collection.
Check whether prompts, responses, tool results, or paths could contain secrets, personal data, customer data, or proprietary code.
List only approved agents in Monitored Agents.
Use the shortest History Window (Days) that meets your needs.
Limit who in your organization can view uploaded sessions in Swif.
Set retention and deletion rules for uploaded data.
Test BYOD devices separately from company-owned devices.
Review risk detection's use of an external LLM provider before turning it on.
The policy doesn't change the AI agents' own logging or privacy settings. Review each agent's storage, cloud processing, and retention separately.
The ADR Sensor is open source under the Apache License 2.0. Review its source code and release history as part of your software supply-chain process.
Change or turn off the policy
To change collection: edit the policy, save it, and let devices check in. A change can take up to 20 minutes to reach a device. The next collection after that uses the new settings.
To stop collection: turn off Enabled or unassign the policy. No new data is collected after devices check in.
Turning off the policy doesn't delete:
the AI agents' own session logs
records already created on the device
sessions already uploaded to Swif
data forwarded to other systems
Follow your retention and deletion procedures for each location.
Troubleshooting
The policy is applied, but no sessions appear
Check that Enabled and Upload Enabled are on.
Check that the device is online and the Swif agent is running.
Check that a monitored AI agent has recent local session data.
Check that the session falls within History Window (Days).
Wait for Collection Interval (Minutes) to pass, then refresh.
Only some AI agents appear
Check that the missing agent is in Monitored Agents, or that the list is empty.
Check that the agent is supported on the device's operating system. Claude Desktop and Warp aren't supported on Linux.
Check that the agent has created local session data.
Older sessions are missing
Increase History Window (Days), up to 30. Also check that the AI agent still has the session locally. The sensor can't collect a session after its records are deleted.
Sessions are collected but don't appear in Swif
Check that Upload Enabled is on.
Check that the device is online and can reach Swif.
Check that you're viewing the correct device and time range.
If the device was offline, wait for it to reconnect and complete another collection.
Sessions arrive every 20 minutes, even with a shorter interval
The device runs Swif agent 1.27.0 or earlier, where intervals under 20 minutes effectively run every 20 minutes. Update the agent to 1.28.0 or later.
Collection uses more resources than expected
Increase Collection Interval (Minutes).
Reduce History Window (Days).
List only the agents you need in Monitored Agents.
Sessions don't have a risk verdict
Check that Risk Detection Enabled and Upload Enabled are both on.
Check the session's Analysis State.
PartialorFailedmeans the analysis didn't complete.
Related resources
Swif


