Skip to content

feat: report agents new to an organization - #6061

Merged
simplesagar merged 3 commits into
mainfrom
grw-66-pr5-agents
Sep 6, 2026
Merged

simplesagar merged 3 commits into
mainfrom
grw-66-pr5-agents

Conversation

@simplesagar

@simplesagar simplesagar commented Sep 4, 2026 •

Copy link
Copy Markdown
Member

Note

Stacked PR — merge bottom-up. Each PR targets the one above it, so its Files tab shows only its own diff.

  1. feat: add the growthsignals activity taxonomy and emitter #6057 — core taxonomy and emitter
  2. feat: forward audited mutations to PostHog #6058 — audit stream to PostHog
  3. feat: report signups as invited or organic #6059 — direct emits: signup source, org created, member joined
  4. feat: report devices appearing in a fleet #6060 — devices
  5. feat: report agents new to an organization #6061 — agents 👈 this PR

Merging #6057 retargets #6058 to main automatically, and so on down the stack.

GRW-66

Last of a five-PR stack. Targets #6060, review that first.

Summary

Emits agent_first_detected when a device-agent scan reports a target the organization has no detection for yet.

The interesting part is what "first" means. The existing read-merge-write in ai_detections is keyed by device serial and user email, because that is the ClickHouse storage key. That makes its notion of "existing" per-device: a harness already known on one laptop looks brand new on the next one, so firing on that signal would announce the same agent once per machine as it spreads through a company.

A separate lookup keyed on nothing but the organization and the target answers the question actually being asked. It runs before the insert, so it describes the organization as it was, and needs no schema change. ReplacingMergeTree may hold unmerged duplicates, which does not matter here: the question is existence, and any surviving row answers it.

Two shape decisions:

  • No actor. Nobody performed this; a device agent scanned and reported what it found. Reporting a user would attribute it to them and attach it to their PostHog person.
  • No project. The detection inventory has no project dimension, so these activities never claim one.

The catalog supplies the display name, with the raw target id kept alongside it so a renamed catalog entry stays traceable.

Motivation

Agents were in scope on the ticket but had no natural signal: they are derived from telemetry rather than stored as detection events, so there was no insert to hook. This uses the read-merge-write the write path already performs, which is what makes it a query rather than a migration.

Temporal actions/month: 0, scales with fixed. No background work is added.


Summary by cubic

Emits agent_first_detected when a device-agent scan reports a target the organization has no detection for yet, completing the agent piece of the GRW-66 PostHog Slack notifications revamp.

  • The existing read-merge-write is keyed by device serial and user email, so a known agent on a new laptop would look brand new; a separate organization-wide lookup now distinguishes genuinely new agents from known ones spreading.
  • The activity carries no actor (a device agent performed the scan) and no project (detections have no project dimension).
  • The catalog supplies the display name, with the raw target id kept alongside so renames stay traceable.
  • Overlapping scans can both pass the pre-insert lookup and both report; the report carries a PostHog $insert_id derived from the organization and target so PostHog collapses the duplicates.

Written for commit 19cbe99. Summary will update on new commits.

Review in cubic

@simplesagar
simplesagar requested a review from a team as a code owner September 4, 2026 04:22
@linear-code

linear-code Bot commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

GRW-66

@changeset-bot

changeset-bot Bot commented Sep 4, 2026 •

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: 19cbe99

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
server Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@simplesagar simplesagar added the enhancement New feature or request label Sep 4, 2026
@cubic-dev-ai

cubic-dev-ai Bot commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

Running ultrareview automatically — This PR adds an organization-wide 'first detected' check inside the AI detection upsert and emits growth signals; it changes a core telemetry function's contract and introduces subtle concurrency and correctness risks in the new existence query, so a deeper review is warranted.. I'll post findings when complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Ultrareview completed in 11m 30s

Review completed against the latest diff

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread server/internal/telemetry/ai_detections.go

@gram-bot gram-bot Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto-approved: review:bypass label applied by @simplesagar. Required status checks still gate this merge.

@simplesagar
simplesagar force-pushed the grw-66-pr5-agents branch 2 times, most recently from 1cd12de to f4f5837 Compare September 6, 2026 19:47
Base automatically changed from grw-66-pr4-devices to main September 6, 2026 20:18
simplesagar and others added 3 commits September 6, 2026 13:18
Emits `agent_first_detected` when a device-agent scan reports a target
the organization has no detection for yet.

The existing read-merge-write is keyed by device serial and user email,
because that is the storage key, which makes its notion of "existing"
per-device: a harness already known on one laptop looks brand new on the
next one. Firing on that would announce the same agent once per machine.
A separate lookup keyed on nothing but the organization and the target
answers the question actually being asked. No schema change.

ReplacingMergeTree may hold unmerged duplicates, which does not matter
here: the question is existence, and any surviving row answers it.

Nobody performs this, so the activity carries no actor: a device agent
scanned and reported what it found. Detections have no project dimension,
so these never claim a project.

Temporal actions/month: 0 (no background work added).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01761VcQZ1sW4TFb16AoozTA
A seed helper in the access tests still called UpsertAIDetections as a
single-value expression. Caught by a whole-module vet rather than the
per-package one, which had not covered this package.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01761VcQZ1sW4TFb16AoozTA
Two scans for the same organization and target can overlap: both pass
the pre-insert lookup, both see the target as unseen, and both report.

Making the claim atomic would cost a lock on a scan path that is
otherwise append-only. Instead the report carries a key derived from what
it asserts — this target was first seen in this organization — so PostHog
collapses the duplicates however many scans raced.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01761VcQZ1sW4TFb16AoozTA
@simplesagar
simplesagar added this pull request to the merge queue Sep 6, 2026
Merged via the queue into main with commit fba020d Sep 6, 2026
44 of 45 checks passed
@simplesagar
simplesagar deleted the grw-66-pr5-agents branch September 6, 2026 20:29
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 6, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

enhancement New feature or request review:bypass Merge without human review approval. Required status checks still apply.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant