Dashboard & activity

Use the shared workspace to inspect connected devices, recorded agent activity, and the context behind findings.

On this page

The dashboard is your team's shared view at app.agentbeam.com. It receives records from connected devices. Local Studio remains useful for activity retained on the machine, including records that did not reach the workspace during a network failure.

Open the right workspace

Sign in and check the workspace identity before investigating activity or changing policy. Your current workspace role controls the visible navigation and server-authorized actions. A workspace member can connect a personal device without receiving the security team's activity access.

Overview summarizes the workspace. Setup helps connect an Agent CLI device and request enterprise MDM access. CLI pairing and MDM activation are independent; a device appearing under Agents is not proof of OS management enrollment.

Investigate activity

Open Activity to browse the records available to your role. Use the page's filters and event details to narrow the relevant agent, time, or risk. Read the summary and findings together with the source and phase of the original event where available.

A captured proposed command establishes what the assistant requested, not what the operating system completed. Heuristic findings identify patterns for review. Confirm effects using additional endpoint or provider evidence when the investigation requires it.

Inspect connected devices

Open Agents to review registered devices and their status. A registered identity means the CLI paired with the workspace; it does not establish continuous capture, a healthy hook, or complete forwarding. Compare recent local activity with dashboard records when diagnosing a silent device.

Authorized operators can revoke a device from this page. Revocation removes its remote access, not its local installation or every historical record. Follow the offboarding guide for complete retirement.

Move from activity to review

Use Risks for flagged records, Policies for workspace restrictions, and Audit log for administrative changes. These views answer different questions: what was observed, how it was assessed, what policy is configured, and who changed the configuration.

Session scorecards and agent evaluation are not implemented in the current dashboard backend. Do not interpret activity totals or a reviewed finding as a per-session compliance score.

When data is missing

Verify beam whoami, beam account, collector status, and a real hook event in Studio. Enrolled forwarding is best-effort and has an in-memory batch; it does not guarantee replay after an outage. Use a redacted local export as separate evidence when needed.

Explore the docs