Skip to main content
Live

43,280 AI events recorded on our own engineering fleet in the last 30 days.

Tracelet / Governance

Put your AI policies into practice.

AI coding activity, the policies that apply and the decisions that need review, in one view. Write policy in plain language, open break-glass access on a timer and see where coverage still falls short.

Become a design partner See how it works
TRACELET.AIGovernanceIllustrative example
Governance / overview

Covered decisions, on the record.

Last 30 days
Live activity
Claude Coderead ~/.aws/credentialsBlockedCursorconnect GitHub MCPAllowedVS Codeconnect unknown:8931 MCPReview
Context attachedAvailable actor, machine, tool, action and policy are in the same record.
Supported activity on enrolled machines
Policy verdict
Blocked by policyBlocked

Claude Code attempted to read ~/.aws/credentials.

Policy: Protect cloud credentials
Decision path
Action observedDonePolicy evaluatedDoneDecision appliedBlocked
Decision record · GOV-4827
Action and outcomeView Policy evaluationView Actor and machine contextView Project contextView
Last modified by Policy engine · Export record
DiscoverControlExplainOne decision record

Illustrative example: covered decisions with the policy, outcome and context attached.

Unapproved tools and sensitive actions

See the tools and the sensitive actions they take.

Detected assistants, MCP servers, skills and plugins appear with the machine and owner. Skills nobody registered start as shadow items until someone reviews them. Supported file, shell and MCP actions are recorded with their context.

Covered activity is visible for review

Policy outcomes

Review the policy outcome where the action happened.

A matching action is allowed, blocked or held for review before it completes. An incident exception goes through a human-approved keycard, for a set window. The policy and the reason stay with the outcome.

Blocked by policy, with the reason

Investigation and evidence export

Investigate from the record, then export it.

Action, policy, outcome and person, machine and project context stay in one decision record. Export it where your review process needs it. The same records feed the posture view.

Decision record ready for review

Policy creation

Describe the intent. The assistant drafts the rules.

Pick the kind of policy, say what you want to govern in plain language and watch the rules take shape beside you. Nothing is created until you review it.

TRACELET.AIPolicies / New policyIllustrative example
  1. 01DescribeCapture intentDrafting
  2. 02ScopeTargets & rolesTargeted
  3. 03ReviewConfirm & createNo rules yet
Step 1 · Describe

What kind of policy is this?

Guardrails

Block or warn on risky agent actions

Selected
MCP

Govern which MCP servers and tools agents may use

Data Protection

Detect and redact PII and secrets

Network

Block or permit an AI tool's network egress on managed machines

Describe what you want to govern

Stop production databases from being dropped, and hold any TRUNCATE on prod hosts for review.

e.g. Block any coding agent from reading cloud credential files.
DescribeScopeReviewDraft · not created yet
Start with recommended rules for your domain
Keycards

Break glass on a timer, with a human holding the key.

Incidents need exceptions. A keycard grants an agent short-lived elevated permissions, and only after a human approver says yes. The grant, the approver and the expiry all land in the record.

Tracelet / Keycards Illustrative example
KeycardsMy requestsGrants

Request short-lived elevated permissions during incidents. A human approver must grant the keycard before your agent can use it.

Approvers: Platform on-call · 1 required
KeycardJustificationRule typeDuration · request / max
restart-stuck-ingest-workers

Restart ingest workers wedged behind the queue backlog.

COMMAND_FILTER15m / 30m Granted · 11m left
rotate-exposed-webhook-secret

Rotate the payments webhook secret after the exposure alert.

FILE_ACCESS30m / 1hRequest access
roll-back-checkout-deploy-revision

Roll the checkout deploy back to the last known-good revision.

FILE_ACCESS15m / 30mRequest access
read-redacted-incident-export

Read the redacted customer export for INC-2291 triage.

CONTENT_FILTER1h / 2hAwaiting approver
RequestApproveExpireEvery grant on the record
AI surface inventory

Find the skills nobody registered.

Every AI-shaped artefact discovered across your fleet: MCP servers, skills, plugins and repos. Most skills arrive as shadow items nobody registered, and review is where they become managed. That is the shadow AI problem at fleet scale: only 21% of organisations have a mature governance model for autonomous AI agents (Deloitte, The State of AI in the Enterprise). Read the State of Shadow AI report.

TRACELET.AIAI Surface InventoryIllustrative example
MCP ServersSkills & RulesPluginsGit ReposDev ToolsDesktop GuardsSBOMVulnerabilities
All42Allowlist9Denylist4Needs review29
Search paths, agents, machines
Skill or rule fileTypeStatusRiskSeen onLast seen
~/.claude/skills/writing-rules/SKILL.mdSKILL_MDShadowMediumClaude Code6 machines2h agoPromoteAllowBlock
~/.cursor/rules/deploy-helpers.mdcCURSOR_RULEShadowMediumCursor3 machines5h agoPromoteAllowBlock
.claude/skills/release-notes/SKILL.mdSKILL_MDManagedLowClaude Code18 machines12m agoAllowlistedBlock
~/.codex/skills/db-migrate/SKILL.mdSKILL_MDShadowMediumCodex1 machine1d agoPromoteAllowBlock
.github/copilot-instructions.mdAGENT_RULESManagedMinimalCopilot24 machines40m agoAllowlistedBlock
Showing 5 of 42 · 29 still need review. Shadow items were discovered on machines but never registered with a policy.
DiscoverReviewManage29 items need review
Control posture

See what is enforced, what is watched and what is still yours.

Control posture across the agent and browser surfaces: what Tracelet automates, what it can only monitor and what still needs your team, including the places it cannot see.

Tracelet / Posture Illustrative example
PostureControlsFrameworksEvidenceExceptionsData Controls
Automated by Tracelet12/12All passing on enrolled machines
Monitored by Tracelet7/92 partial · no data yet
Needs your team4/62 awaiting evidence
Surface × StrengthControls · pass / fail
PreventsDetects
Agent
8 controls7 pass · 1 fail
6 controls6 pass · 0 fail
Browser
Not offered by design
5 controls3 pass · 2 fail
Fix first2 findings
AGT-CRED-READ-DETECT-ONLYHigh

Credential file reads are detected but not blocked on 3 machines.

Agent · PreventsSwitch Protect cloud credentials from warn to enforce.
BRW-PLUGIN-COVERAGE-GAPMedium

The browser plugin is missing on 11 of 40 enrolled machines.

Browser · DetectsPush the browser plugin through your MDM profile.
Known blind spots
  • Incognito and guest browser profiles are not captured.
  • Findings on browser events only fire where the browser plugin is deployed.
  • Machines that have not checked in for 7 days leave the denominator.
PreventsDetectsNeeds your teamBlind spots listed
Compliance evidence

Show the auditor what ran, not what the policy says.

Control status for ISO 27001 and SOC 2 is computed from what agents observed: findings, MCP inventory, proxy traffic and machine check-ins. Generate an evidence pack on demand or on a schedule and get it by email as PDF or structured data, with every suppression, override and grant listed in one exceptions register. Tracelet maps the evidence to your programme; the certification stays yours.

TRACELET.AIComplianceIllustrative example
FrameworksControlsEvidence packsExceptionsBulletins

Control status is computed from what agents observed on enrolled machines, not from a policy document. Every pack below is a signed, exportable artifact.

FindingsProxy trafficMCP inventoryAgent heartbeats
FrameworksControls · pass / partial / fail / no data
ISO 27001Annex A · mapped controls
14 of 20 passing
Pass
14
Partial
3
Fail
1
No data
2
SOC 2Trust Services Criteria · mapped controls
9 of 12 passing
Pass
9
Partial
2
Fail
0
No data
1
Evidence packs On demand or scheduled
SOC 2 Type II · last 12 months Ready · PDF and JSON

Governance hygiene, tool policy, MCP inventory, findings, exceptions, trust grants

Download
ISO 27001 Annex A · quarterlyScheduled

Scheduled · next run 1 Oct · emailed to security@ when ready

Generate now
Bulletin check · npm advisory 09-12Partial

Pasted advisory verified against the fleet · 2 machines still affected

Open report
Packs are emailed when ready. Nobody waits on generation.
MapVerifyExportEvidence from live telemetry
Design partners

Start the conversation. One call to establish fit and how we would work together.

Become a design partner