Full Conversation Replay - Every Prompt, Tool Call, and File Access
Reconstruct complete Claude Code sessions turn by turn, with the file operations, shell commands, MCP connections, and per-turn cost that came with them.
"Something Happened" Is Not an Investigation
An AI agent deleted a production config file. A credential appeared in a public repository. A vulnerable package shipped to production. In each case the question is the same: what exactly did the agent do, what was it asked to do, and what changed as a result?
Process-level telemetry cannot answer that. It shows a binary that ran and files that changed. It cannot show the prompt that triggered the change, the tool call the model chose, or the MCP server that received the data.
Session Reconstruction from Deep Telemetry
Sessions are reconstructed on the endpoint and streamed to the dashboard with sub-second latency. Nothing is sampled and nothing is summarized away.
- Complete conversation timeline - user prompts, assistant responses, and every tool call in sequence
- File operations - every read, write, and edit performed by the agent, with path and context
- Shell command logging - full command text, working directory, and execution context
- MCP server connections - which external tool servers the AI reached and what it sent
- Subagent relationships - parent/child session mapping when the AI spawns background agents
- Cost attribution - per-turn input, output, cache read, and cache write tokens with model-aware pricing
- Session metadata - duration, project and repo context, model selection, git branch
Live Floor
The Live Floor shows every active AI session across the fleet as it happens: who is running what, in which repo, on which model, with live token burn. Sessions stream in with sub-second latency, so an in-progress incident is visible while it is still in progress.
The Forensic Record

Captured Per Session
| Dimension | Detail |
|---|---|
| Per turn | Prompt text, response text, tool invocations, input/output/cache-read/cache-write tokens, model, computed cost |
| File operations | Read, write, and edit events with path and surrounding context |
| Shell commands | Full command text, working directory, execution context |
| MCP | Server destination and payload metadata for each connection |
| Subagents | Parent/child session mapping for background agents |
| Session metadata | Duration, project/repo, git branch, model selection, user, device |
| Transport | Encrypted end to end with mutual TLS; buffered locally and replayed on reconnect, so an offline laptop loses nothing |
| Retention | 7 days (Community) · 30 days (Team) · 90 days (Business) · custom (Enterprise) |
Controls This Evidences
- ISO A.8.16
- Monitoring activities - real-time AI conversation telemetry across every endpoint
- NIST AU-2
- Event logging - AI agent actions recorded as auditable events
- NIST AU-6
- Audit record review, analysis, and reporting
- HIPAA §164.312(b)
- Audit controls - record and examine activity in systems with ePHI
See Kraitos AIDR in Action
Deploy in 60 seconds. Get answers in 24 hours. Stop guessing what your AI-augmented organization is doing.
[email protected]kraitos.io