Source: bob-wire c21.inventory — Inventory + Users/Devices split, from the 2026-08-31 Mark Peterson advisor call
One person's full picture — the drill from Users / Devices. The workstation ↔ identity ↔ agent chain stays visible — "we need to maintain the relationships… for compliance and accountability." Sessions live here now (they left Inventory, §2.7): a session belongs to a user, flowing user → device → agent → session. Switch the person; every state below is derived from the shared fixtures.
Devices & agents — the chain
Accounts
The account referenced on every inference call — where this person's usage actually flows.
Personal account, same device as the enterprise org. IP sent here has none of the enterprise data protections — 2 of 5 sessions below ran on it. The obvious control is block personal accounts — this cycle observes; enforcement comes later.
What they're doing
Heavy ChatGPT use for proposals and outbound copy — splits between the enterprise org and a personal account.
actual tool-call data from the sensor — the summary above is derived, this is measured
Sessions
This person's sessions — they live here, not on Inventory. Click one for the full receipt (what ran, as whom, what it touched, what it cost).
| Started | Session | Agent | Dur | Tokens | Summary | Account |
|---|---|---|---|---|---|---|
| 1h ago | ChatGPT | 40m | 380k | Drafted the enterprise pricing one-pager from call notes | enterprise | |
| 21h ago | ChatGPT | 55m | 520k | Polished the Meridian proposal deck copy | personal acct | |
| 3d ago | ChatGPT | 35m | 300k | Summarized six discovery calls into an objection-handling doc | enterprise | |
| 3d ago | ChatGPT | 30m | 260k | Rewrote the outbound email sequences for the security-buyer segment | personal acct | |
| 5d ago | ChatGPT | 45m | 410k | Built the ROI comparison table for the CISO deck | enterprise |
Composition notes
- Sessions attach to users (§2.7): the list lives here, removed from Inventory. It stays a list — the c77 session receipt/anatomy view is the click-through, not inlined.
- The chain is the hero (§2.9): device → agent instance → account rendered as one linkage per row, with sensor state on the device and monitored state on the instance. Two pages, one graph — this is the people lens.
- Monitored vs detected-only first-class (§2.5): Hermes on jonah's sensored MacBook is detected by the install scan but unmonitored, has no account, and produces zero sessions — three different absences, each shown as itself.
- Personal accounts unmissable (§2.6, §5): Dana's gmail-shaped ChatGPT account sits beside the enterprise org on the same device; her personal-account sessions are flagged in place. Observation only — the block-personal-accounts control is pointed at, not built.
- Coverage honesty: alexis renders the "we know nothing" state truthfully — seat held on the enterprise account, no sensor, zero telemetry → investigate banner, empty chains, empty sessions. Zero rows is a statement about the sensor, not the person.
- Cross-filter drill (§2.3): View in Inventory carries ?user=<id> — the call's drill path (pick a user, land in Inventory double-filtered), link back implied by this page's back button.
- Tokens/$ toggle: both kept per Mark P — "both are just ways of gauging the flow." Share-of-fleet derives from the usage trend's trailing 30 days, in whichever unit is active.
- Open — attribution: will agent-on-behalf-of attribution always be knowable? The unattributed Codex instance lives on the Inventory page; this page assumes a person exists, but its empty/unknown states are designed for attribution failing, not just sensors missing.
- Open — denominator: devices come from Okta/Jamf (source per device shown), not from the sensor. Whether "fleet" means sensored devices or the whole org affects every count here.