Users / Devices
User Detail v1

Source: bob-wire c21.inventory — Inventory + Users/Devices split, from the 2026-08-31 Mark Peterson advisor call

One person's full picture — the drill from Users / Devices. The workstation ↔ identity ↔ agent chain stays visible — "we need to maintain the relationships… for compliance and accountability." Sessions live here now (they left Inventory, §2.7): a session belongs to a user, flowing user → device → agent → session. Switch the person; every state below is derived from the shared fixtures.

dana = personal account · kamal = engineer texture · jonah = Hermes · alexis = coverage gap
"both are just ways of gauging the flow"
DW
Dana WhitfieldGTMheavy
dana · identity from jamf (dana-mbp) — the Okta/Jamf denominator, not what the sensor happens to see
View in Inventory →
42Mtokens · 30d
13% of fleet flow
1device
1 of 1 sensored
2agent instances
2 monitored · 0 detected-only
5sessions · 30d
2 on a personal account

Devices & agents — the chain

person → device → agent instance → accountone graph, read from the people side · sensor state per device, monitored state per instance
▪ dana-mbpmacbookjamf✓ sensor
ChatGPT1.2025.196monitoredlast seen 1h agoorg-qpoint-8xk22enterprise
ChatGPT1.2025.196monitoredlast seen 20h agouser-dw72hfqb (dwhitfield.72@gmail.com)personal

Accounts

The account referenced on every inference call — where this person's usage actually flows.

OpenAIorg-qpoint-8xk22enterprisein use · 8 users org-wide
OpenAIuser-dw72hfqb (dwhitfield.72@gmail.com)personalin use · 1 user org-wide

Personal account, same device as the enterprise org. IP sent here has none of the enterprise data protections — 2 of 5 sessions below ran on it. The obvious control is block personal accounts — this cycle observes; enforcement comes later.

What they're doing

LLM-derived summary

Heavy ChatGPT use for proposals and outbound copy — splits between the enterprise org and a personal account.

Observed tool-calling surface
MCP serversgoogle-driveslack
Reposnone — non-engineering workflow

actual tool-call data from the sensor — the summary above is derived, this is measured

Sessions

This person's sessions — they live here, not on Inventory. Click one for the full receipt (what ran, as whom, what it touched, what it cost).

StartedSessionAgentDurTokensSummaryAccount
1h agoChatGPT40m380kDrafted the enterprise pricing one-pager from call notesenterprise
21h agoChatGPT55m520kPolished the Meridian proposal deck copypersonal acct
3d agoChatGPT35m300kSummarized six discovery calls into an objection-handling docenterprise
3d agoChatGPT30m260kRewrote the outbound email sequences for the security-buyer segmentpersonal acct
5d agoChatGPT45m410kBuilt the ROI comparison table for the CISO deckenterprise
1 device → 2 agent instances → 5 sessions · 30d1 of 15 people known to Okta/Jamf · as of 2026-08-31 17:00ZView in Inventory — same graph, technology lens, pre-filtered →

Composition notes

  • Sessions attach to users (§2.7): the list lives here, removed from Inventory. It stays a list — the c77 session receipt/anatomy view is the click-through, not inlined.
  • The chain is the hero (§2.9): device → agent instance → account rendered as one linkage per row, with sensor state on the device and monitored state on the instance. Two pages, one graph — this is the people lens.
  • Monitored vs detected-only first-class (§2.5): Hermes on jonah's sensored MacBook is detected by the install scan but unmonitored, has no account, and produces zero sessions — three different absences, each shown as itself.
  • Personal accounts unmissable (§2.6, §5): Dana's gmail-shaped ChatGPT account sits beside the enterprise org on the same device; her personal-account sessions are flagged in place. Observation only — the block-personal-accounts control is pointed at, not built.
  • Coverage honesty: alexis renders the "we know nothing" state truthfully — seat held on the enterprise account, no sensor, zero telemetry → investigate banner, empty chains, empty sessions. Zero rows is a statement about the sensor, not the person.
  • Cross-filter drill (§2.3): View in Inventory carries ?user=<id> — the call's drill path (pick a user, land in Inventory double-filtered), link back implied by this page's back button.
  • Tokens/$ toggle: both kept per Mark P — "both are just ways of gauging the flow." Share-of-fleet derives from the usage trend's trailing 30 days, in whichever unit is active.
  • Open — attribution: will agent-on-behalf-of attribution always be knowable? The unattributed Codex instance lives on the Inventory page; this page assumes a person exists, but its empty/unknown states are designed for attribution failing, not just sensors missing.
  • Open — denominator: devices come from Okta/Jamf (source per device shown), not from the sensor. Whether "fleet" means sensored devices or the whole org affects every count here.

Qpoint Brand Style Guide