Skip to main content
Live

575K+ AI events recorded on our own engineering fleet in the last 30 days.

Tracelet / AI control plane

One platform.  Every altitude.

The developer

Own spend, score and session quality. Coaching, not surveillance.

The team lead

Fleet keep rate, output and a per-developer productivity leaderboard.

The CXO

An enterprise AI scorecard: net value, risk and compliance, export-ready.

The control path

From first signal
to accountable decision.

One MCP call. Four checks.
Follow an agent’s request from discovery to the decision your team can review.

The agent’s task

“Summarise this week’s customer feedback.”

Illustrative example
Inventory finding01 / 04

A new tool enters the picture.

Tracelet identifies the server and the machines that can reach it.

Server
unknown:8931
Registration
Not in the approved inventory
Seen on
dev-04 · dev-11 · dev-18
Unregistered server found

Start with the tools your team already uses.

One inventory, one policy model and one decision record across the tools in use; a logo shows an integration, not identical enforcement everywhere.

On your devices

Engineering AI11

  • Visual Studio Code
  • Visual Studio Copilot
  • GitHub Copilot
  • Anti Gravity
  • Kiro
  • Claude Code
  • Claude Cowork
  • Windsurf
  • Cursor
  • Devin
  • ChatGPT Codex
In your browser

Browser AI4

  • ChatGPT
  • Claude
  • Perplexity
  • Grok
Supported operating systems
  • macOS
  • Windows
  • Linux
One control planeTracelet
  • Shared inventory
  • Central policy
  • Decision records
Coverage varies by tool and action. We confirm what applies before your rollout.
63% of organisations have no AI governance policy at all (IBM, 2025 Cost of a Data Breach Report). Read the State of Shadow AI report
Inside the control plane 01 · Verdicts

One action.
Seven possible verdicts.

Stop an action, ask for human input, or let it continue with a record. Priority-ordered rules determine the response.

Proposed actionShell · file · MCP · prompt
Tracelet policy enginePriority-ordered rules → one verdict
  • Stop the action

    Block

    Denied before it runs.

  • Human input

    Approve

    Step-up confirmation in the tool.

  • Human input

    Justify

    Runs once a reason is given.

  • Human input

    Request access

    An admin grants one-time access.

  • Continue with a record

    Redact

    Runs with a scrubbed record.

  • Continue with a record

    Warn

    Runs and notifies the developer.

  • Continue with a record

    Log

    Runs and records the action.

Every verdict is recorded.First block short-circuits evaluation. Failure behaviour is configured as fail-open or fail-closed.
What a verdict looks like in the tool

The same policy engine answers in the chat window, the desktop app and the terminal. Two hard blocks and one justification gate, shown where the developer sees them.

Claude CoworkIllustrative example
Drop the stale tables from the analytics DB.
Blocked by Tracelet policy (Pre-Tool-Use)
Command matches blocked command: DROP TABLE
VerdictBlockDenied before it runs
Codex · desktopIllustrative example

kubectl delete ns staging was blocked by the local policy layer, so I couldn’t tear the namespace down directly.

If you want, I can submit the false-positive review for this block next.

Ask anything…
VerdictBlockReview requested in the tool
Terminal · agent sessionIllustrative example
$kubectl exec -it db-primary-0 -- psql
That kubectl exec command got blocked by Tracelet (org governance policy on this machine), asking for a quick justification before it’ll allow it.
Why do you need to run this? Diagnosing prod DB perf for issue #1798
Accepted. Retrying.
$kubectl exec -it db-primary-0 -- psql
VerdictJustifyRuns once a reason is given

Illustrative product UI · no real data · names, commands and tickets are invented.

Inside the control plane 02 · MCP gateway

One endpoint.
Per-user credentials.

One URL for MCP clients. The gateway checks policy and roles, fetches the caller’s credential from Vault, and records the call.

One client endpoint /v1/mcpTwo meta-tools search_toolsexecute_tool
Your clients

MCP clients

  • Claude Code
  • Cursor
  • Any MCP client

One governed route to upstream tools.

MCP call
Tracelet

MCP Gateway

  1. 01
    Evaluate policy

    Apply priority-ordered tool policies.

  2. 02
    Check server access

    Filter by role. An empty server list denies access.

  3. 03
    Fetch the credential

    Vault supplies this user’s provider credential.

Per-user access
Your upstreams

MCP servers

Remote servers

Streamable HTTP

Local processes

Sandboxed stdio containers

Every call writes a proxy audit event.Tool policies, proxy policies and roles are authored centrally.
Inside the control plane 03 · Identity

Your directory.
One source of identity.

Sync users and groups through Keycloak. Assign roles to people, teams and service accounts, with explicit permission checks on every API route.

Your existing directory
  • Google Workspace
  • Microsoft Entra ID
  • LDAP · SAML/OIDC
KeycloakScheduled sync
Tracelet

Access hub

Users
Federated from your identity provider.
Teams
Mapped to identity-provider groups.
Roles
Assigned to users, teams and service accounts.
Service accounts
Separate credentials and lifecycle.
People use SSOSign in through your identity provider.
Automation has its own identityService accounts never impersonate a person.
Permissions are explicitEvery API route checks access.
Inside the control plane 04 · Decision record

Every decision.
The reason behind it.

Capture the actor, action, matched policy and verdict at decision time, with the context a reviewer needs later.

Decision recordIllustrative example
Blocked

Credential file read prevented.

Actor
Developer via SSO
Machine
dev-04
Action
file.read → ~/.aws/credentials
Policy
Protect cloud credentials
Reason
Credential file access denied by policy.
Context captured at decision time
Kept for review

One decision.
The context to explain it.

Findings
Issues raised for review
Decision Log
Resolution and reason
Policy Overrides
The justification trail
Access Requests
One-time access decisions
Audit Log
Actor, action and outcome

Gateway and proxy activity retain an audit trail too.

Bring context in. Send findings out.

Identity and repository context attach the person, machine and change to each record; findings go to the people and systems that act on them.

Identity & access

Attach the person, team and permissions.

  • Google Workspace
  • Microsoft Entra ID
  • Active Directory / LDAP
  • OIDC / SAML
Owner attached

Repository context

Link the finding to its source change.

  • GitHub
Change linked
TraceletFinding
Illustrative example

Production change

Owner
Engineering
Source
GitHub
Review requiredRoute to the responsible team
Context, decision & evidence together

Service desk

Route the finding to your service desk

  • ServiceNow
  • Jira
  • Zendesk
  • Freshdesk
Review task with an owner

Security operations

Send findings to security operations

  • Splunk
  • Elastic
  • Datadog
  • Webhooks
Finding with context

From source context to an owned finding, in the systems your team already uses.

How deployment and privacy work
Design partners

Start the conversation. One call to establish fit and how we would work together.

Become a design partner