Docs

AI Graph

Visualize and explore the interrelationships among AI Actors, MCP servers, tools, resources, data assets, and policies.

AI Graph is the governed view of how everything in the mesh connects — actors, MCP servers, tools, resources, data assets, and the policies protecting them.

The backend model is a directed edge: a (src_type, src_id) → (dst_type, dst_id, edge_type) row, written idempotently so re-running discovery doesn't duplicate the graph. Building the graph for display collects every distinct node referenced by an edge, then resolves a human-readable name for each from the matching catalog table — MCP server, tool, resource, model version, agent, application, dataset, table, column, prompt template, or role — so the page never shows a bare UUID.

The page itself has four tabs. By MCP and By Role are flat card lists; By Actor groups agents into confidence bands — observed, approved, curated, blocked — with observed shown first since those are the actors still waiting on operator review. The fourth tab, AI Estate, is the unified graph: every governance path laid out across five columns (Identity → MCP Server → Capability → Data Asset → Column), with each hop colored by the real policy decision that applies there — deny, conditional, allow, or unprotected — derived from actual policy bindings on the subject and target, not a static label.

Clicking a node in the unified graph isolates every path running through it and dims the rest; tables and columns stay collapsed by default and only appear on click (or automatically when a parent has ten or fewer children), so a large MCP's fan-out doesn't overwhelm the canvas. Every node opens a detail panel with its full hop-by-hop chain.

That detail panel is also where the graph turns into action: a Create Policy button scoped to whatever was clicked — MCP-wide, one tool, one table, one column, one role, or one agent — deep-links straight into the Policy Builder pre-filled with that scope. When a path reaches a sensitivity-tagged node over a hop with no policy at all, a dedicated "Protect …" callout surfaces automatically, so the highest-risk gap on a path is the one an operator is nudged toward first.

Reference

Features

Entity relationship visualization
description
Renders every recorded relationship among actors, MCP servers, tools, resources, and data assets as a graph, with each node's name resolved from the catalog instead of shown as a raw ID.
Path exploration
description
Traces the complete chain from a subject through an MCP server to the tools, tables, and columns it can reach, laid out left to right so a whole access path reads as one line; deeper levels expand on click rather than rendering all at once.
Actor-centric views
description
Groups AI Actors by confidence state — observed, approved, curated, blocked — with newly observed actors surfaced first since they still need operator review.
Role-centric views
description
Lists synced IdP roles alongside a standing All Users tile representing policies with no subject restriction, so role-scoped and unrestricted governance are both visible in one place.
MCP-centric views
description
Lists MCP servers as cards showing health, tool and resource counts, and policy mode, each linking through to that server's own detail page.
Policy protection state
description
Colors each hop in a path by the policy decision that actually applies there — deny, conditional, allow, or unprotected — computed from real policy bindings on the subject and target, not a static label.
Contextual policy creation
description
A Create Policy button on the path detail panel, scoped to whatever node was clicked — MCP-wide, a single tool, table, column, role, or agent — that deep-links into the Policy Builder pre-filled with that scope.

Interfaces

data-plane serves /ai-graph
data-plane serves /lineage
note
internal legacy alias route