Cortex Sensor
Cortex Sensor is an application installed on your device. It runs in the background, captures activity from supported AI tools, and syncs that activity to your organization's Cortex workspace. The synced activity is available in the Cortex dashboard based on each person's role and visibility.
To get started, sign in with your work account, configure the approved sources you use, and confirm that a prompt appears in Cortex. After setup, Sensor continues running in the background.
For the designated admin and IT
Chaos Labs will create your organization and designate an initial admin. The admin will complete organization onboarding, download the signed .pkg or .exe, and coordinate deployment with IT. Jamf has been tested for macOS and Microsoft Intune has been tested for Windows, so most employees will not need to install Sensor themselves.
Start with Deploy Cortex Sensor.
For employees
For most employees, IT installs Cortex on a managed device. Employees do not need to download or run an installer.
Follow this order:
- Set up Cortex Sensor
- Supported providers and surfaces
- Verify Sensor setup
- Control capture and sync
- Troubleshoot Sensor
For developers
Use Fix Sensor port conflicts only when a local development process conflicts with Cortex's required ports.
After Sensor is capturing and syncing successfully, continue to Roles and visibility in the Cortex dashboard.
How capture works
AI source → capture path → local capture → workspace sync
- You enable a supported command-line tool, browser, desktop app, local-history source, or MCP source.
- Cortex captures new activity from the source or imports completed Cursor IDE conversations.
- The activity appears in Home → Activity.
- If the device is enrolled and workspace sync is healthy, Cortex syncs the capture to the organization workspace for use in the Cortex dashboard.
Running means Sensor is ready to capture activity. To verify setup, send a new prompt, find it in Home → Activity, and confirm workspace sync is healthy.
What Sensor can capture
Fields vary by source and provider. A capture can include:
| Data | Examples |
|---|---|
| AI request and response content | Prompts, messages, and generated responses |
| Source and model context | CLI, browser, desktop, or MCP channel; application, provider, and model |
| Request metadata | Capture time, duration, status, conversation, and exchange identifiers |
| Usage metadata, when available | Input, output, cache, and thinking-token counts |
| Tool activity, when supported by the path | Tool definitions, calls, results, and captured local MCP activity |
| Capture quality | Whether the request and response are complete, partial, or contain errors |
Sensor does not capture every action on the device or all network traffic. It captures activity only from supported sources with capture enabled. Local capture and workspace sync are separate: if sync is temporarily unavailable, supported activity can still be captured locally but will not appear in the Cortex dashboard until sync recovers.