- Coding assistants — Claude Code (CLI) and Claude Desktop — are captured by the local
watcher, which reads their session transcripts and uploads completed turns to
data.enfors.ai. It reads files only; no proxy, no TLS interception, no certificate. This replaces the earlier mitmproxy approach. - Agent SDKs (e.g. the OpenAI SDK) call the Enfors gateway (
llm.enfors.ai) directly, where each call is captured and enqueued.
This section is the buyer- and IT-facing summary. A complete IT & CISO Deployment
Package — with the watcher/gateway internals and the MDM (Jamf/Mosyle) rollout runbook — is
available under NDA from your Enfors representative.
What it does
- Captures LLM / agent–human sessions, identity, and context — who, when, how.
- Records the full decision record: inputs, evidence, reasoning trace, tool activity, findings, artifacts, operational telemetry, and metrics.
- Gives IT and AI leadership visibility into who is using what, when, and how much.
- Enables cost allocation and ROI measurement across the AI workforce.
- Discloses itself to the monitored user: the Enfors mark is shown in the macOS menu bar or the Windows system tray exactly while capture is active (see the menu bar / tray indicator).
What it does not do
- It does not modify the content of AI conversations.
- For coding assistants, it does not run a proxy, intercept traffic, or install a certificate — the watcher only reads the local transcript.
- It does not touch provider authentication or credentials.
How it’s deployed
What the system answers
- What did our agents produce? — an inventory of meaningful outputs per session.
- What are people using AI for? — use-case classification by person, team, and tool.
- Is this a one-off or a pattern? — behavioral signatures over time, so recurring work worth standardizing is distinguished from episodic exploration.
In this section
Data captured vs. not captured
What’s captured (gateway + watcher), what is never captured, and the PII nuance.
Data residency & retention
Region, encryption, and retention periods.
Tenant isolation & access
Row-Level Security and access controls.
Network & TLS
Connection paths and endpoints for the gateway and the watcher.
Security controls summary
The control-by-control summary and how to get the full package.
Enterprise deployment
Fleet rollout via MDM (Jamf/Mosyle).