CortexDocumentation
Portal · Activity

Activity

Find captured AI sessions, narrow the view, and open the evidence behind a user, model, tool, or time window.

  • Session evidencePeople, tools, models, and timing
  • Trace detailTranscript, files, topics, actions, and plans
  • Operational analyticsTokens, cost, latency, and model usage
From signal to session evidence

Activity is the fastest way to confirm that Cortex is receiving new work. Each row represents a captured session, with the person, tool, models, timing, and estimated spend attached.

What Activity shows

  • Person: The signed-in user associated with the captured session.
  • Session: One continuous run of a supported tool or AI application.
  • Models: The providers and models used during the session.
  • Timing: First and last captured activity.
  • Estimated spend: A planning estimate for the captured activity.

Inspect a session

ViewUse it to answer
Session overviewWho worked, when it happened, and which models were used
TranscriptWhat the user and model exchanged
Files and topicsWhich context and subjects appeared
Actions and securityWhich tools ran and which security signals were detected
Plans and analyticsHow the work unfolded, plus tokens, cost, and latency

Use filters to narrow the list before opening a session. Keep the selected date range with any number you share.

If expected activity is missing

  • Any path: Send a new prompt from a configured source. Existing sessions do not pick up new routing settings.
  • Endpoint capture: Confirm Cortex Defender is running, the source is enabled, and cloud sync has no backlog.
  • Centralized capture: Confirm the Cortex Gateway URL and header are correct, then verify the personal capture token used for attribution.
  • Portal check: Open Coverage to see whether the path is inactive or not configured.
Do not treat an empty Activity view as proof that no AI work happened. It means no matching activity was captured for the current scope and filters.

Go deeper

Was this helpful?