The time period
The selector in the top right — Last 24 Hours, Last 7 Days, Last 30 Days (the default), Last 90 Days, Last 6 Months or Last 12 Months — sets the window for everything below the three count cards. Each window is rolling and ends at the current time. Unlike the usage dashboards, the Dashboard groups activity into hours, days and months in your browser’s timezone, so two admins in different timezones can see different per-day figures for the same window.The count cards
These are current totals, not activity. They don’t change with the time period, and a server or agent with no traffic still counts. Each card links to its list page.
Monitored Actions
Policy decisions over the window, with three cards above a line chart:
These count policy decisions, not completed tool calls. A call that was allowed and then failed on the MCP server still counts as allowed, and a call that needed approval counts as allowed whether or not anyone approved it.
Beneath each count is a rate and a comparison, for example
2 / day • 40 in previous 30 days (↑ 50%):
- The rate divides by the number of periods that had activity, not by the length of the window. A 30-day window with activity on only 10 days divides by 10, so the rate reads as “per active day”. The unit is hours for Last 24 Hours, months for Last 6 Months and Last 12 Months, and days otherwise.
- The comparison is against the window of the same length immediately before this one.
Top Users
The ten most active users in the window, with two columns:
Actions counts audit events, not tool calls. A single tool call records more than one event — the policy decision and the call itself, for example — so a user’s Actions is typically higher than their number of tool calls.
Only servers that are currently active count. Activity on a server that has since been deleted or deactivated is left out of both columns, which keeps MCP Servers Used from exceeding the total.
Selecting a row opens Audit History for that user over the same window.
Top Usage
The five most active AI Agents and the five most active MCP Servers in the window, each ranked by Actions — audit events, as in Top Users. Activity with no recorded agent or server name is left out. Unlike Top Users, this card isn’t limited to currently active servers, so a server removed during the window can still appear.Tool Calls
The ten busiest tools in the window, one row per MCP server and tool:
Like Monitored Actions, the counts are policy decisions. Decisions made by Data Control Center runtime policies are left out.
Type comes from the tool’s own metadata when Barndoor has it. Otherwise it’s inferred from the tool’s name — names starting with verbs like create, update, delete or send read as Write, and get, list, search or fetch as Read. Anything else shows Unknown rather than guessing.
Frequently asked
Why is a user's Actions count much higher than the calls they made?
Why is a user's Actions count much higher than the calls they made?
Actions counts audit events, and a tool call usually records more than one. Use Top Users to compare users against each other, and the MCP Usage Dashboard — grouped by User — for call counts.
Why does the '/ day' rate look too high?
Why does the '/ day' rate look too high?
It divides by days that had activity, not by every day in the window. A burst of activity on a few days produces a high per-day rate even over a long window.
Why don't these numbers match the MCP Usage Dashboard?
Why don't these numbers match the MCP Usage Dashboard?
The two count different things. The MCP Usage Dashboard counts MCP messages proxied through the gateway; the Dashboard counts policy decisions (Monitored Actions, Tool Calls) and audit events (Top Users, Top Usage). The Dashboard also groups by your browser’s timezone, while the MCP Usage Dashboard defaults to UTC.