CortexDocumentation

Cortex Sensor

Updated

Cortex Sensor is an application installed on your device. It runs in the background, captures activity from supported AI tools, and syncs that activity to your organization's Cortex workspace. The synced activity is available in the Cortex dashboard based on each person's role and visibility.

To get started, sign in with your work account, configure the approved sources you use, and confirm that a prompt appears in Cortex. After setup, Sensor continues running in the background.

For the designated admin and IT

Chaos Labs will create your organization and designate an initial admin. The admin will complete organization onboarding, download the signed .pkg or .exe, and coordinate deployment with IT. Jamf has been tested for macOS and Microsoft Intune has been tested for Windows, so most employees will not need to install Sensor themselves.

Start with Deploy Cortex Sensor.

For employees

For most employees, IT installs Cortex on a managed device. Employees do not need to download or run an installer.

Follow this order:

  1. Set up Cortex Sensor
  2. Supported providers and surfaces
  3. Verify Sensor setup
  4. Control capture and sync
  5. Troubleshoot Sensor

For developers

Use Fix Sensor port conflicts only when a local development process conflicts with Cortex's required ports.

After Sensor is capturing and syncing successfully, continue to Roles and visibility in the Cortex dashboard.

How capture works

AI source → capture path → local capture → workspace sync

  1. You enable a supported command-line tool, browser, desktop app, local-history source, or MCP source.
  2. Cortex captures new activity from the source or imports completed Cursor IDE conversations.
  3. The activity appears in Home → Activity.
  4. If the device is enrolled and workspace sync is healthy, Cortex syncs the capture to the organization workspace for use in the Cortex dashboard.

Running means Sensor is ready to capture activity. To verify setup, send a new prompt, find it in Home → Activity, and confirm workspace sync is healthy.

What Sensor can capture

Fields vary by source and provider. A capture can include:

DataExamples
AI request and response contentPrompts, messages, and generated responses
Source and model contextCLI, browser, desktop, or MCP channel; application, provider, and model
Request metadataCapture time, duration, status, conversation, and exchange identifiers
Usage metadata, when availableInput, output, cache, and thinking-token counts
Tool activity, when supported by the pathTool definitions, calls, results, and captured local MCP activity
Capture qualityWhether the request and response are complete, partial, or contain errors

Sensor does not capture every action on the device or all network traffic. It captures activity only from supported sources with capture enabled. Local capture and workspace sync are separate: if sync is temporarily unavailable, supported activity can still be captured locally but will not appear in the Cortex dashboard until sync recovers.

Was this helpful?