AI Insights Architecture Overview

In a Foglight Cloud deployment, Foglight AI Insights and the MCP Server are both hosted in the Foglight Cloud, so no relay or network-boundary crossing is required. The AI client connects directly to the cloud-hosted MCP Server over an encrypted channel. The MCP Server then calls the Foglight Cloud APIs and services—such as Performance Investigation (PI), TopSQL, GraphQL, and alarm services—and returns the results to the AI client.




This design does the following:

  • Keeps AI access within the managed Foglight Cloud boundary.
  • Removes the need to expose or configure on-premises endpoints.
  • Uses cloud-native authentication and encryption to keep AI access controlled and authenticated.

How the architecture works

The following steps describe how monitoring data flows from your environment to the AI client:

  1. Monitoring agents collect telemetry from the target environment.
  2. The Foglight Agent Manager forwards the telemetry to Foglight Cloud.
  3. Foglight Cloud stores, correlates, and serves the data through Foglight APIs and related services.
  4. The AI client connects directly to the cloud-hosted MCP Server.
  5. The AI client calls supported tools, such as alarm checks, PI queries, TopSQL analysis, or GraphQL topology searches.
  6. The MCP Server calls the relevant Foglight API or service and returns the results to the AI client.

This flow aligns AI access with your existing Foglight Cloud platform instead of replacing it.

Security boundaries

The architecture maintains clear boundaries between the following layers:

  • The AI client layer
  • The MCP integration layer
  • The Foglight Cloud platform and its APIs
  • The monitored infrastructure and telemetry collection layer

These boundaries let the AI client access operational data while Foglight Cloud retains full governance and control. The AI client never calls monitoring APIs directly. The MCP Server always acts as the controlled intermediary.