Skip to content Skip to main navigation Skip to footer

Monitoring Employee AI Web Activity in Cyfin & CyBlock

Applies to: Cyfin and CyBlock · How to report on — and dig into — employees’ use of AI tools.

Introduction

As generative AI tools like ChatGPT and Grok become part of everyday work, organizations need to monitor their use for productivity, compliance, and security. Cyfin and CyBlock classify AI-related web activity under the standard Artificial Intelligence category, so you can track it in the same reports you already use. Reporting is identical in both products (shared code), so everything below applies to either one.

Reporting centers on Sessions — a session reconstructs a user’s continuous engagement with a site into a single, readable event, filtering out background noise — with Session Duration giving accurate engaged-time. (For definitions, see the Terms Glossary; for the full report list, see the Report Glossary; for the category itself, see the Category Glossary.)

Two ways to consume the data:

  • Standard reports — scheduled PDF/HTML templates, ideal for automated email distribution.
  • Visualizer — interactive, login-based dashboards for real-time, self-service exploration by managers or HR.

Both use the same underlying data.

Before you start: make sure your URL List is current (Categorization → URL List → Download) so AI sites are categorized, and confirm the Artificial Intelligence category is classified per your policy (Categorization → Customize → Classification).


Session reports on AI activity (recommended)

Session reports appear in the standard report list and focus on engaged-time (Sessions and Session Duration), giving clean timelines without background-hit noise — ideal for AI monitoring. Run them from Reports → Manager: select the report, configure settings, time frame, groups/IDs, and the category or sites you want, then Run Now or Schedule.

Session Analysis (high-level, per user)

Shows every session for a user over a period — App/Site name, start, stop, and duration — with one-click drill-down to the URLs in a session.

For AI activity:

  1. Select Session Analysis under High-Level Summary Reports.
  2. Choose a specific user (under Groups and IDs).
  3. Run the report.
  4. In the output, sessions for AI tools appear in the timeline under the Artificial Intelligence category; drill down for detail on any AI session.

Session Audit Summary (per AI tool)

Shows every session to a specified App/Site (or several), including user, start, stop, and duration, with drill-down to the URLs in each session.

For a specific tool (e.g., ChatGPT or Grok):

  1. Select Session Audit Summary under Audit Detail Reports.
  2. Under Sites, enter the tool’s URL (e.g., chatgpt.com; separate multiple with commas).
  3. Select users/groups as needed.
  4. Run the report. The output lists sessions by user on that AI site; drill down for granular URL data.

Summary views for AI trends

To see AI usage across the organization or a group without full URLs:

  • Session Analysis (above) rolls up sessions by category, so the Artificial Intelligence category’s share of activity is visible at a glance.
  • Site Analysis gives a high-level audit by classification, category, group, and user (hit- and byte-based), useful for spotting where AI activity concentrates.
  • Top Users and Top Web Sites help identify which people and which AI sites stand out, so you can then run a focused session report on them.

Audit detail reports (forensic)

When you need full URLs, timestamps, and per-user detail:

Category Audit Detail — all AI category activity

  1. From Reports → Manager, select Category Audit Detail under Audit Detail Reports.
  2. Under Select When to Run, choose Run Now or Schedule.
  3. Under Settings, set Report Delivery (Wait / E-Mail / Save), Format (HTML/PDF), Report View (Read-Only or Interactive), and Data Configuration/Network if you have multiples.
  4. Under Time Frame, pick a Date Range or Custom range.
  5. Under Groups and IDs, select the users/groups (Browse to check boxes, or Select to enter specific IDs with wildcards like *name).
  6. Select the Artificial Intelligence category.
  7. Choose your URL detail level (single-line, full, or text).
  8. Run the report. Use the report filters (IP, user, URL) to refine — for example, filter the URL for chatgpt to isolate that tool.

User Audit Detail — one user, filtered to AI

  1. Select User Audit Detail under Audit Detail Reports; configure as above (choose specific users/groups, not Enterprise).
  2. Run the report.
  3. In the Audit Detail section, use the category filter to select Artificial Intelligence only. This shows that user’s chronological AI visits with full URLs.

Reports on specific AI tools

AI tools (ChatGPT, Grok, etc.) are recognized Applications/Sites within the Artificial Intelligence category. For tool-specific analysis:

  • Site Audit Detail — from Audit Detail Reports; under Sites, enter the tool’s URL (e.g., chatgpt.com; multiple separated by commas). Lists activity chronologically with group/user/hourly summaries.
  • Site Audit Summary — the same, summarized without full URLs.

Visualizer dashboards

For interactive, visual monitoring, use the Visualizer (login-based, self-service). Build dashboards with charts (bar, line, pie, table) focused on the Artificial Intelligence category or a specific tool, showing Sessions and Session Duration. Ideal for real-time exploration and drill-down; combine with scheduled standard reports for full coverage.


Capturing what users search or input into AI (firewall-dependent)

The reports above show which AI tools were used, by whom, and for how long. Depending on your firewall, you may be able to capture an additional level of detail — what users actually search for or input into AI tools — which then flows into the AI reports alongside everything else.

Cyfin with Palo Alto: Palo Alto Networks firewalls offer an AI module that, once enabled, provides Cyfin with this additional input-level detail to report on. Enable the module on the Palo Alto side; the added detail then appears in your Artificial Intelligence category reports.

Other firewalls: the availability of input-level detail depends on your firewall’s capabilities. If you’re interested, check what your firewall can log, or contact Wavecrest Technical Support to see what’s supported for your setup.

CyBlock: for CyBlock, this deeper input-level detail is handled on a per-deployment basis and requires SSL inspection. If it’s something you need, contact Wavecrest sales to discuss the options for your environment.


Tips and best practices

  • Schedule it. Automate a recurring AI usage summary (e.g., weekly) for ongoing oversight.
  • Use interactive reports to drill from summaries into detail in one place.
  • Align to policy. Classify the Artificial Intelligence category as Acceptable, Unacceptable, or Neutral to match your acceptable-use policy so it’s color-coded correctly in reports.
  • Custom templates. Build report templates (Reports → Templates) with AI-focused sections for repeatable output.
  • Combine standard + Visualizer. Scheduled reports for distribution; Visualizer for interactive daily views.
  • If AI data is missing, verify your log/data configuration and that your URL List is current.

For assistance, contact support@wavecrest.net.

Related Articles