Pages
Inventory — Companies v1

Source: bob-wire c21.inventory — Inventory + Users/Devices split, from the 2026-08-31 Mark Peterson advisor call

The technology half of the c21 split: Inventory becomes all about the agents and technologies — companies → technologies → instances, rolled up. Machines, sessions, and per-user rows moved to Users / Devices; a user survives here only as a filter, arriving pre-applied via drill-through (?user=dana). Monitored vs detected-only is first-class, and accounts & licensing surface where the inference calls reveal them.

Monitored
92
%
23 of 25 instances · 2 detected-only
Companies
5
Technologies
7
Instances
25
Tokens · 30d
293
m
attributed to people
Spend · 30d
$2,007
across 12 active people

open q: does "fleet" mean the sensored devices or the whole org? These numbers count what the sensor + egress see; the Okta/Jamf denominator and coverage framing live on Users / Devices.

Companies

vendor → technology → instanceopen q: label TBD for the technology level — "AI agents" vs "harnesses" (used interchangeably on the call)
Company
Technologies
Instances
Monitored
People
Tokens · 4w
Anthropic
claude-opus-4-6claude-sonnet-4-5
299 / 99217M
OpenAI
gpt-5.2gpt-5.2-codex
21010 / 10864M
xAI
grok-4
121 / 2
1 detected-only
212M
Google
gemini-3-pro
133 / 3319M
Nous Research
hermes-4-70b
110 / 1
1 detected-only
12M

25 instances across 7 technologies from 5 companies — 1 of them unattributed (rendered as a first-class row, not hidden).

2 detected-only instances Grokkai-winonboard →Hermesjonah-mbponboard → seen by install scan or egress signal — no session telemetry from either

Accounts & licensing

3 enterprise · 1 personal · 1 unknown

Every inference call references an account — so licensing posture is observable, per technology and per person. The ops person knows the corporate org ids; everything else is signal.

ProviderAccountLicensingPeople
Anthropicorg-qpoint-2ab41enterprise10
OpenAIorg-qpoint-8xk22enterprise8
OpenAIuser-dw72hfqb (dwhitfield.72@gmail.com)personal1
Googleqpoint.io-ws-C03kf9enterprise3
xAIteam-7cc19f3eunknown2
no account at all:Hermes— local model, $0, nothing referenced on any call
13 people hold seats across these accounts→ Users / Devices
personal account on a corporate device
Dana Whitfield — ChatGPT, personal
user-dw72hfqb (dwhitfield.72@gmail.com)

Used alongside the enterprise org on the same device (dana-mbp) — 2 of her last 5 ChatGPT sessions ran on the personal account. Personal accounts don't carry the enterprise data protections: "none of our IP goes to a personal ChatGPT account."

annotation: ghost affordance only — this cycle is observation mode (§5). Visibility first; the block control is the obvious next step, not this page's job.

unknown account:team-7cc19f3e seen on Grok calls from Marcus Chen and Kai Nakamura — no agreement on file; ops can't map it to anything. "Other account IDs alone is pretty good signal."

Models & usage

12 weeks · fleet-wide

The drift story: Anthropic-heavy through June → the OpenAI experiment ramps gpt-5.2 from mid-July → grok-4 arrives in the last three weeks, and Hermes flickers on locally at $0 from mid-August. Tokens and dollars are both just ways of gauging the flow.

ModelCompanyTrend · 12wTokens · 12w
claude-sonnet-4-5Anthropic

377M
claude-opus-4-6Anthropic

297M
gpt-5.2OpenAI

121M
gemini-3-proGoogle

51M
grok-4xAI

12M
hermes-4-70bNous Research

2M

Surface

MCP servers & repos · fleet-wide

MCP servers

9 distinct
github5 people
google-drive5 people
slack5 people
postgres2 people
figma1 person
filesystem1 person
hubspot1 person
linear1 person
sentry1 person

Repos

6 distinct
qpoint/qtap3 people
qpoint/qplane2 people
qpoint/qbench1 person
qpoint/qplane-ui1 person
qpoint/qtap-installer-win1 person
qpoint/qtap-tools1 person

Composition notes

  • The split, applied (§2.1–2.2, 2.7): no machines, no sessions, no per-user rows anywhere on this page — those moved to /pages/users-devices-v1. Inventory is agents, harnesses, surface, activity, trends.
  • Users as a filter, not a dimension (§2.3): ?user=dana arrives pre-applied from Users / Devices or user detail, renders as a removable chip, and narrows instance lists and surface. Any person name in an instance row applies the same filter in place — the drill path is symmetric.
  • Company → technology → instance is the hero (§2.4): five vendors as organizing rows via vendorRollup(), expanding to technologies, each listing its instances (person, device, monitored, account, version, last seen). One-to-many, rolled up.
  • Monitored vs detected-only is first-class (§2.5): the headline %, the per-company coverage cell, and the actionable strip all derive from monitoredStats(). Hermes on jonah-mbp and Grok on Kai's unsensored Windows box are the two detected-only rows — detected is not monitored.
  • Accounts & licensing live in Inventory (§2.6, §5): posture from accountPosture(). Dana's personal ChatGPT account is deliberately unmissable; the "Block personal accounts" button is a ghost affordance annotated as future enforcement — observation mode this cycle, not an enforcement UI.
  • Identity attribution isn't assumed (§6): the unattributed Codex CLI instance (org key at egress, no person, no managed device) renders as a first-class row with a "no identity" treatment, not hidden.
  • Derivation ethic: every number comes from the fixture helpers (vendorRollup / monitoredStats / accountPosture / fleetTotals / allInstances / usageTrend); nothing hand-typed. The 30d person-attributed total (~293M) is deliberately below the trend's trailing 30d (~314M) — the gap rides the unattributed instance.
  • Open question — label TBD: "AI agents" vs "harnesses" for the technology level. The page says "technologies" in structure and annotates rather than decides.
  • Open question — fleet denominator: does fleet = sensored devices or the whole org? This page counts what the sensor/egress see and says so; the Okta/Jamf denominator belongs to Users / Devices.

Qpoint Brand Style Guide