Product · Coverage
Know what Tallin can observe and control.
Visibility comes from the sources you connect. Enforcement comes from supported admin actions and the traffic you route through Tallin. They are different capabilities, shown with their source and scope.
Know what each connection can tell you
See the source. See the limits.
Approved workspace connected
A matched identity still does not prove which provider account was used.No workspace connection
A visit does not establish account type or reveal the prompt.Inline checks applied
Controls apply only to requests routed through Tallin.Read each claim in context
Observed does not mean controlled.
A provider API may report usage that never crossed the Gateway. That usage can be observed without being subject to gateway limits. A browser finding may establish a service visit without establishing the provider account used.
Check source health and recency alongside the label. Optional sources are choices; a failure in a source you configured needs a specific next action.
- OBSERVED
- Observed: direct evidence from a connected source, such as a gateway event, provider usage record, or managed-browser hostname observation. Each record states what the source establishes; identity and account attribution may remain unresolved.
- INFERRED
- Inferred: a conclusion drawn from supporting signals, such as a likely AI subscription found in an expense record. The source and the inference remain distinct.
- ENFORCED
- Enforced: a configured control applied through a supported execution path. Gateway controls govern routed requests; provider or identity access actions have their own permissions and scope.
- NOT COVERED
- Not covered: activity or actions for which no configured source or control provides coverage. Direct provider activity may still be observed through connected APIs without Gateway routing. Tool and MCP side effects are not controlled unless they pass through a supported enforcement path.
Choose the evidence and controls you need.
Review your providers, source permissions, and selected gateway workloads with us before rollout.