
- Claude Code exports OpenTelemetry traces from Claude Code itself, configured through Claude managed settings. Use it when you need Claude Code’s model requests and tool runs step by step, not only prompts.
- Claude Compliance and OpenAI Compliance read transcripts, including assistant replies, from the vendor’s compliance API. They require that vendor’s enterprise plan.
All access is read-only. The Falcon API client needs only the AIDR read
scope, and Openlayer never changes anything in your Falcon tenant.
How it works
Once connected, Openlayer reads AIDR events from the Falcon API and turns them into inference data.- Discovers agent products. Falcon tags every prompt and agent session with the product that produced it, such as Claude Code or Codex. Each product Falcon reports appears under Products.
- Gives each product its own project. By default, a newly discovered product is enabled into a
new
CrowdStrike · <product>project, so each agent can be governed separately. Products that are not enabled do not sync. - Pulls on a schedule. Openlayer syncs every 10 minutes by default.
- Writes prompts first, activity later. Each prompt becomes a row as soon as Openlayer sees it. Tool calls and model usage follow in an Agent activity row once the session goes idle.
Prerequisites
- A CrowdStrike Falcon tenant with the Falcon AIDR module, and the Falcon sensor on the machines where developers run AI agents.
- AIDR API access turned on for the tenant. When it is off, Falcon rejects every AIDR request with 403, even for an API client with the right scope.
- A Falcon API client with the AIDR read scope, created below.
- An Openlayer workspace where you are an admin. Connecting, changing settings, enabling, disabling, or moving products, and disconnecting are admin-only. Members can view products and their projects.
Create the Falcon API client
In the Falcon console, go to Support and resources → API clients and keys and create an API client with only the Aidr Events: Read scope. Copy the client ID and the secret. Falcon shows the secret only once. Also note your tenant’s region: the Falcon cloud your console runs on. For example,falcon.crowdstrike.com is US-1 and falcon.eu-1.crowdstrike.com is EU-1. Openlayer
supports US-1, US-2, US-3, EU-1, US-GOV-1, and US-GOV-2.
The CrowdStrike Developer Center covers API clients in
general, and FalconPy is a quick way to check a client’s
credentials and region outside Openlayer.
Setup guide
Step 1: Connect
In Openlayer, go to Settings → Integrations and open CrowdStrike Falcon AIDR in the AI Usage & Security section. Enter the Client ID, Client secret, and Region (US-1 by default). Click Test connection to check the credentials without saving them, then click Connect.
Step 2: Review the sync settings
Open the General tab. Under Settings:- Periodic sync pulls new prompts and agent activity. Turn it off to pause syncing without disconnecting, or click Sync now to queue a sync immediately.
- Sync frequency is Every 10 minutes, Every 30 minutes, or Every hour.
- Create a project for new products is on by default. See Products and projects.

Products and projects
The Products tab lists every AI agent product Falcon AIDR has reported, with its name and Falcon’s numeric product tag (for example, Claude Code and213584428666146), status, project, sessions
seen, and imported prompts. A product
appears after a sync once Falcon reports activity for it.

- On (the default) — Openlayer enables the product into a new
CrowdStrike · <product>project and pipeline. If a plan limit or a missing permission blocks the project, the product stays disabled and shows the reason. - Off — the product stays disabled until an admin enables it.
- Change project sends the product’s new rows to another project and pipeline. Rows already written stay in the previous project; they are not moved or copied.
- Disable stops syncing the product. Its project, pipeline, and existing data are kept.
- Re-enabling a disabled product opens on the project it already had, so it does not create a second project. The product shows backfilling while Openlayer reads its sessions from the last 7 days, then returns to idle and syncs new activity.
What lands in Openlayer
Falcon AIDR records what people ask AI agents and what the agents do, not what the agents answer. It returns prompts, tool-call inputs, models, and token counts. It does not return assistant responses or tool output, so every row’s output is empty. Openlayer writes two kinds of rows into the product’s pipeline:

- Tool calls are not attached to prompts. Falcon gives tool calls no timestamp, so Openlayer cannot tell which prompt caused them. They are grouped into the session’s activity row instead.
- Resumed sessions get a follow-up row. If a session picks up again after its activity row is written, the new calls land in another Agent activity row. Rows are never rewritten.
- Sessions are preserved. Each AIDR agent session becomes one Openlayer session.
- Users are attributed only when unambiguous. The user ID is the OS user who ran the agent, and only when exactly one OS user ran agents on that host. Otherwise the user is anonymous.
- Cost is estimated. Openlayer estimates cost on the model-usage step from the model and token counts.
- Long values are cut. A prompt or tool input longer than 50,000 characters ends with
… [truncated].
Evaluating the ingested data
Once rows are flowing, evaluate AI agent usage the same way you evaluate application traffic:- Create tests on prompts and token usage. Tests that score a response have nothing to score, because outputs are empty.
- Detect PII in the prompts people send to coding agents
- Use governance frameworks to evidence AI-usage controls with real traffic