Analytics

Analytics

List view
Quick Start
User Guide
Policies & GuardRails
Witness Anywhere: Remote Device Security
Witness Attack
Administrator Guide
 

Analytics Overview

The Analytics page provides configurable analytics reports for insight into all of the GuardRails activity over your choice of time ranges. Analytic reports are also available for Witness Anywhere devices, Security Operations data sent to your SIEM from WitnessAI, and Return on Investment based on the metrics you specify.

Guardrails Analytics

All of the Guardrails Analytics reports operate in the same way.
As documented in the Console & Settings section, choose your desired Date Range (1) for analysis, and the report will update.
Click the Export as PDF link (2) to download a PDF of the currently displayed report. You will not be prompted to choose a download location or file name. The report will automatically be saved in your browser’s Download Location folder, with the name of the GuardRail, for example Behavioral Activity.pdf, or Data Protection.pdf.
notion image
 
Clicking Export as PDF will download a PDF of the currently displayed report. No prompt will be displayed. The PDF will automatically be saved to the download location specified in your browser.

Behavioral Activity

Track user behavior based on their prompt activity, as classified by WitnessAI's models. This view helps you understand what users are trying to achieve with their prompts to AI models. Behaviors can be controlled by enabling the Behavioral Activity Guardrail in Policies.
notion image

Data Protection

Understand how sensitive information is being protected within your organization. Track the top users, destinations and prompts that have triggered Data Protection Guardrails. You can manage your coverage by enabling the Data Protection Guardrail in Policies.
notion image

Organizational Behavior

Gain insight into macro trends within your organization, as detected by WitnessAI's models. See which employees might be leaving the organization, and the top groups triggering detections. To track more, enable Alerts within the Organizational Behavior Guardrail in Policies.
notion image

Risk Analysis

Monitor potential risks to your organization, as detected by WitnessAI's models. Track the top users triggering risks, the most common blocked intentions, and the most frequently blocked models. You can expand your coverage by enabling the Risk Analysis Guardrail in Policies.
notion image

Model Protection

Safeguard your organization's models from potential threats, including jailbreaks and prompt injections. Monitor the top blocked intentions for protected models. To increase your coverage, enable the Model Protection Guardrail in Policies.
notion image

Harmful Response

Monitor harmful responses from AI models to user prompts, such as self-harm and illegal activities. Track the top users triggering harmful responses, the top intentions, and the number of blocks over time. To broaden your protection, enable the Harmful Response Prevention Guardrail in Policies.
notion image

Platform

Witness Anywhere

Witness Anywhere protects managed devices in an unmanaged environment. Track the top users, blocked activities, and intentions while off the corporate network. Witness Anywhere is configured in Settings > Proxy Configuration.
Witness Anywhere provides valuable insights and metrics on your remote users and their portable devices. The Sankey diagram below is useful for a quick understanding of a large amount of data. This report shows all the Models an individual User connects to, and all the Users that connect to an individual Model, enabling a quick triage on a single page.
notion image

SOC Dashboard

Monitoring the alerts and metrics shared with your Security Operations Center (SOC) enables AI developers and management have a common view of what’s happening in their environment, facilitating easier communication and understanding on both teams. Track the top alerts, newest alerts, and the AI applications producing them. Monitor the percentage of blocked vs. allowed prompts, and which policies are blocking them.
notion image

ROI

Gather metrics that help assess your Return on Investment (ROI). For example, blocked inbound connections show policy enforcement over time. You can also track prompts routed to internal models. This analysis can aid in finding unexpected usage, and identifying opportunities to consolidate AI usage on fewer models. Demonstrating the effectiveness of internal model usage as external usage decreases is another popular use case.
Let us know which metrics would help you the most.
notion image

Auto-Refresh

Auto-refresh Settings
  1. In the footer of any Analytics report’s last panel, hover over the small timer icon. An “Auto-refresh” tooltip will display.
  1. Clicking on the timer icon displays the refresh interval picker.
  1. Choose your desired auto-refresh interval.
notion image
  1. Once chosen, the timer icon will turn green, and show an animated countdown until the next auto-refresh.
  1. Hovering over the timer icon displays the countdown to the next refresh.
notion image
 
Fullscreen Display
  1. Hovering over the double-angle icon will display an “Enter fullscreen” icon.
notion image
 
  1. Clicking the Enter fullscreen icon converts the Analytics report into a dark mode display.
    1. The display is scrollable. It can also be resized with the standard browser zoom-in and zoom-out.
      Press and hold the keyboard’s “Escape” or “esc” key to exit the fullscreen display.
notion image