Actor Activity
Inspect runtime behavior by AI Actor.
Actor Activity is a per-subject rollup: one row per distinct caller (subject_id_hash) that has invoked anything through governed infrastructure in the selected window (1h, 6h, 24h, 7d, or 30d — a shared selector used across most Cockpit tabs). It answers "who is calling what" at the individual-actor level, as opposed to the server- or tool-centric views elsewhere in Cockpit.
Identity resolves through the agent catalog: a subject with a matching gcdm_agents row gets its registered name and confidence_state; a subject with no catalog entry is still listed, not dropped — labeled observed-<hash prefix> with a confidence state of observed. This is the mechanism by which unregistered or "shadow AI" callers stay visible instead of disappearing from the dashboard.
Each row reports invocation count, deny count and deny rate, the actor's single most-called tool in the window (picked by a window-scoped ranking, not just the latest), summed input and output tokens, and last-seen timestamp. The table is capped at 200 rows, ordered by invocation volume — the busiest actors surface first.

Docs