Cockpit Overview
Summarize runtime activity and governance health.
Cockpit Overview is the landing tab of AI Cockpit — a fixed, 24-hour snapshot of everything moving through governed AI traffic, built entirely from aggregate queries over gcdm_invocations. Unlike every other Cockpit tab, it has no window selector: the backing query always defaults to the last 24 hours, and the page auto-refreshes every 15 seconds rather than on demand.
Four KPI cards lead the page: total invocations, active AI actors (distinct agents seen), active MCP servers, and denied calls. Below them, a line chart buckets invocations and denies by hour so a spike or a drop in traffic is visible at a glance without leaving the tab.
Three "Top 5" lists follow — MCP servers, tools, and AI actors, each ranked by invocation count over the same 24-hour window. Names resolve through the catalog (MCP server and agent tables) where known; the tools list is sourced from spec.jsonrpc_method on the invocation record, a simplification that currently only reflects the edge-sidecar telemetry shape. Actors without a catalog entry are still listed, labeled observed-<hash prefix> rather than dropped — the same shadow-AI-visibility pattern used throughout Cockpit.
A final panel splits invocation counts by collection source: calls routed through the FaburAI gateway versus calls observed by a Policy Enforcer sidecar deployed alongside a customer's own proxy. It exists as a migration parity check — as edge-sidecar deployment rolls out, gateway-collected volume should trend toward zero while edge_sidecar's climbs, and this panel is how that transition gets verified rather than assumed.

Docs