Activity Feed
Review chronological runtime and governance events.
Activity Feed is the raw, reverse-chronological log of individual invocations, paginated (50 per page by default, up to 500, via limit/offset) rather than aggregated — where every other Cockpit tab shows a rollup, this one shows the actual events behind it. Each row joins an invocation to its decision-log outcome, resolved actor name, and resolved MCP server name.
Displayed columns are timestamp, actor, server, tool, a color-coded decision badge (allow/deny/warn), and the name of the first rule that matched. The underlying query also carries call duration and token counts on every row, but the current table does not render those two columns — they are available in the API response, not yet surfaced in the UI.
The only filter exposed in the UI is decision (All / Allow / Deny / Warn), meant for drilling straight into denied calls. The API accepts three more filters server-side — actor, MCP server ID, and tool — but nothing in the current page wires those controls up, so they are only reachable by hand-constructing the request's query string.

Docs