Skip to main content

Collectors overview & coverage

A collector captures AI activity from one layer of the environment and forwards it to the Lumen control plane with metadata and any local detection verdict. The console's Collectors page mirrors this family and marks what is available today. Collectors group by where the code runs:

GroupCollectorsRuns
Host-local, the hard partEndpoint agent + Browser extensionOn the managed device
Instrument-the-codeApplication SDK, Agentic MCP proxy, OpenTelemetryIn the built AI system
Network and platformGateways for LiteLLM, Kong and Portkey, Cloud for Bedrock and logsAt the API boundary, or in the cloud account

Coverage matrix​

Four of these surfaces are covered today: developer AI tooling, MCP traffic, browser AI on four providers, and LiteLLM gateways. The rest are designed and not yet built, and the Inline enforce column states the intent for those rather than behaviour in hand. Each planned collector repeats the same note at the head of its own page. macOS is the supported endpoint platform today; see what the installer does on each platform.

SurfaceCollectorsAvailabilityInline enforce?
Developer AI tooling, such as Claude Code, SDKs and CLIsEndpoint agent proxy + hooksAvailableYes
Agentic MCP traffic, in both directions between client and serverMCP proxyAvailableYes
AI use in browsers: ChatGPT, Claude, Perplexity and GeminiBrowser extensionAvailable; Gemini in preview. Other AI sites, such as Copilot and Poe, are only discoveredPrompts: redact or block in-page. Responses: best-effort, and recorded only on Gemini
Internal applicationsApplication SDK + inline APIPlannedYes, pre and post model call
LiteLLM gatewayGateway plugin, with a co-located agentAvailableYes
Kong and Portkey gatewaysGateway pluginPlannedYes
Cloud platforms such as AWS BedrockCloud ingestionPlannedLog or redact, asynchronous
OpenTelemetry GenAI telemetryOTel receiverPlannedLog, for observability

Every collector can raise every detection class.

How an interaction flows​

  1. Capture. A collector observes one AI interaction: the request with its prompt, model and parameters, or the response, or both, possibly streamed token by token.
  2. Enrich. Metadata is attached: user identity, device id, application or process, collector id, provider and model, tenant id.
  3. Evaluate. The collector's policy runs. Access rules decide whether and how to process. Prompt rules inspect the content. The local fast-path returns the inline verdict. A deeper cloud detection tier that would run asynchronously is planned and not built.
  4. Act. Log, Redact, or Block.
  5. Ship. The interaction and its verdict are spooled and drained to the Lumen cloud over outbound-only HTTPS.
  6. Correlate. Findings power the console dashboards. Export to the Wazuh Indexer is planned and not yet available.

Inline vs monitor​

For Block and Redact the collector must sit in the data path and get a synchronous verdict. The endpoint proxy, the MCP proxy and the browser extension do. The SDK and the gateway plugins are designed to. For Log-only a collector may observe out of band, from cloud logs or mirrored traffic. The inline latency budget is a first-class design constraint: the verdict is local and takes single-digit milliseconds, and the cloud never sits in the request path.