AI coding activity, the policies that apply and the decisions that need review, in one view. Write policy in plain language, open break-glass access on a timer and see where coverage still falls short.
Action and outcomeView Policy evaluationView Actor and machine contextView Project contextView
Illustrative example: covered decisions with the policy, outcome and context attached.
Unapproved tools and sensitive actions
See the tools and the sensitive actions they take.
Detected assistants, MCP servers, skills and plugins appear with the machine and owner. Skills nobody registered start as shadow items until someone reviews them. Supported file, shell and MCP actions are recorded with their context.
Covered activity is visible for review
ActivityTools and actions on enrolled machines
Last 30 days
Claude Coderead ~/.aws/credentialsBlocked
Cursorconnect GitHub MCPAllowed
VS Codeconnect unknown:8931 MCPReview
Context attachedAvailable actor, machine, tool, action and policy are in the same record.
Policy outcomes
Review the policy outcome where the action happened.
A matching action is allowed, blocked or held for review before it completes. An incident exception goes through a human-approved keycard, for a set window. The policy and the reason stay with the outcome.
Blocked by policy, with the reason
Policy outcomeProtect cloud credentials
Last 30 days
Claude Code attempted to read a restricted credential fileBlocked
Actor
Platform engineer · dev-04
Action
Read ~/.aws/credentials
Policy
Protect cloud credentials
Reason
This credential file is restricted by policy.
Policy outcomeBlocked by policy
The read was stopped on the machine before it ran.
Action observed
Policy evaluated
Decision applied
Investigation and evidence export
Investigate from the record, then export it.
Action, policy, outcome and person, machine and project context stay in one decision record. Export it where your review process needs it. The same records feed the posture view.
Decision record ready for review
Decision recordDecision GOV-4827
Last 30 days
Ready for investigationOne decision, with the available context attached.
Describe the intent. The assistant drafts the rules.
Pick the kind of policy, say what you want to govern in plain language and watch the rules take shape beside you. Nothing is created until you review it.
TRACELET.AIPolicies / New policyIllustrative example
01DescribeCapture intentDrafting
02ScopeTargets & rolesTargeted
03ReviewConfirm & createNo rules yet
Step 1 · Describe
What kind of policy is this?
Guardrails
Block or warn on risky agent actions
SelectedMCP
Govern which MCP servers and tools agents may use
Data Protection
Detect and redact PII and secrets
Network
Block or permit an AI tool's network egress on managed machines
Describe what you want to govern
Stop production databases from being dropped, and hold any TRUNCATE on prod hosts for review.
e.g. Block any coding agent from reading cloud credential files.
Break glass on a timer, with a human holding the key.
Incidents need exceptions. A keycard grants an agent short-lived elevated permissions, and only after a human approver says yes. The grant, the approver and the expiry all land in the record.
Tracelet / Keycards Illustrative example
KeycardsMy requestsGrants
Request short-lived elevated permissions during incidents. A human approver must grant the keycard before your agent can use it.
Approvers: Platform on-call · 1 required
KeycardJustificationRule typeDuration · request / max
restart-stuck-ingest-workers
Restart ingest workers wedged behind the queue backlog.
COMMAND_FILTER15m / 30m Granted · 11m left
rotate-exposed-webhook-secret
Rotate the payments webhook secret after the exposure alert.
FILE_ACCESS30m / 1hRequest access
roll-back-checkout-deploy-revision
Roll the checkout deploy back to the last known-good revision.
FILE_ACCESS15m / 30mRequest access
read-redacted-incident-export
Read the redacted customer export for INC-2291 triage.
Every AI-shaped artefact discovered across your fleet: MCP servers, skills, plugins and repos. Most skills arrive as shadow items nobody registered, and review is where they become managed. That is the shadow AI problem at fleet scale: only 21% of organisations have a mature governance model for autonomous AI agents (Deloitte, The State of AI in the Enterprise). Read the State of Shadow AI report.
TRACELET.AIAI Surface InventoryIllustrative example
See what is enforced, what is watched and what is still yours.
Control posture across the agent and browser surfaces: what Tracelet automates, what it can only monitor and what still needs your team, including the places it cannot see.
Show the auditor what ran, not what the policy says.
Control status for ISO 27001 and SOC 2 is computed from what agents observed: findings, MCP inventory, proxy traffic and machine check-ins. Generate an evidence pack on demand or on a schedule and get it by email as PDF or structured data, with every suppression, override and grant listed in one exceptions register. Tracelet maps the evidence to your programme; the certification stays yours.
Control status is computed from what agents observed on enrolled machines, not from a policy document. Every pack below is a signed, exportable artifact.