Docs

Tool and Resource Activity

Inspect usage and policy coverage across tools and resources.

Tool and Resource Activity is two tables on one tab: Tools, grouped by (tool name, MCP server) from the tool_name recorded on each invocation, and Resources, anchored on the resource catalog. Both exist to answer the same question from opposite directions — is everything actually receiving traffic covered by a published policy.

The Tools table reports invocation count, deny count and deny rate, distinct callers, and a policy_count — the number of published policy bindings attached directly to that tool. When a tool has live invocations but zero attached policy bindings, has_policy_gap goes true and the UI marks it with a warning icon next to the tool name: traffic flowing through a tool nothing is explicitly governing.

The Resources table is catalog-anchored rather than traffic-anchored, so every registered resource appears even if nothing has touched it. It carries the same policy-gap flag and count, but not a working access count yet — the underlying query does not currently link resource access back to individual invocations, so usage volume per resource isn't available here even though the column exists in the response shape; only the catalog listing and policy coverage are real today.

Reference