One platform. Every altitude.
Own spend, score and session quality. Coaching, not surveillance.
Fleet keep rate, output and a per-developer productivity leaderboard.
An enterprise AI scorecard: net value, risk and compliance, export-ready.
The control path
From first signal
to accountable decision.
One MCP call. Four checks.
Follow an agent’s request from discovery to the decision your team can review.
“Summarise this week’s customer feedback.”
A new tool enters the picture.
Tracelet identifies the server and the machines that can reach it.
- Server
- unknown:8931
- Registration
- Not in the approved inventory
- Seen on
- dev-04 · dev-11 · dev-18
Start with the tools your team already uses.
One inventory, one policy model and one decision record across the tools in use; a logo shows an integration, not identical enforcement everywhere.
Engineering AI11
- Visual Studio Code
- Visual Studio Copilot
- GitHub Copilot
- Anti Gravity
- Kiro
- Claude Code
- Claude Cowork
- Windsurf
- Cursor
- Devin
- ChatGPT Codex
Browser AI4
- ChatGPT
- Claude
- Perplexity
- Grok
- Shared inventory
- Central policy
- Decision records
One action.
Seven possible verdicts.
Stop an action, ask for human input, or let it continue with a record. Priority-ordered rules determine the response.
- Stop the action
Block
Denied before it runs.
- Human input
Approve
Step-up confirmation in the tool.
- Human input
Justify
Runs once a reason is given.
- Human input
Request access
An admin grants one-time access.
- Continue with a record
Redact
Runs with a scrubbed record.
- Continue with a record
Warn
Runs and notifies the developer.
- Continue with a record
Log
Runs and records the action.
The same policy engine answers in the chat window, the desktop app and the terminal. Two hard blocks and one justification gate, shown where the developer sees them.
DROP TABLEkubectl delete ns staging was blocked by the local policy layer, so I couldn’t tear the namespace down directly.
If you want, I can submit the false-positive review for this block next.
kubectl exec command got blocked by Tracelet (org governance policy on this machine), asking for a quick justification before it’ll allow it.Illustrative product UI · no real data · names, commands and tickets are invented.
One endpoint.
Per-user credentials.
One URL for MCP clients. The gateway checks policy and roles, fetches the caller’s credential from Vault, and records the call.
/v1/mcpTwo meta-tools search_toolsexecute_toolMCP clients
Claude Code
Cursor
- Any MCP client
One governed route to upstream tools.
MCP Gateway
- 01Evaluate policy
Apply priority-ordered tool policies.
- 02Check server access
Filter by role. An empty server list denies access.
- 03Fetch the credential
Vault supplies this user’s provider credential.
MCP servers
Streamable HTTP
Sandboxed stdio containers
Your directory.
One source of identity.
Sync users and groups through Keycloak. Assign roles to people, teams and service accounts, with explicit permission checks on every API route.
Google Workspace
Microsoft Entra ID
- LDAP · SAML/OIDC
Access hub
- Users
- Federated from your identity provider.
- Teams
- Mapped to identity-provider groups.
- Roles
- Assigned to users, teams and service accounts.
- Service accounts
- Separate credentials and lifecycle.
Every decision.
The reason behind it.
Capture the actor, action, matched policy and verdict at decision time, with the context a reviewer needs later.
Credential file read prevented.
- Actor
- Developer via SSO
- Machine
dev-04- Action
file.read → ~/.aws/credentials- Policy
- Protect cloud credentials
- Reason
- Credential file access denied by policy.
One decision.
The context to explain it.
- Findings
- Issues raised for review
- Decision Log
- Resolution and reason
- Policy Overrides
- The justification trail
- Access Requests
- One-time access decisions
- Audit Log
- Actor, action and outcome
Gateway and proxy activity retain an audit trail too.
Bring context in. Send findings out.
Identity and repository context attach the person, machine and change to each record; findings go to the people and systems that act on them.
Identity & access
Attach the person, team and permissions.
Google Workspace
Microsoft Entra ID
Active Directory / LDAP- OIDC / SAML
Repository context
Link the finding to its source change.
GitHub
Production change
- Owner
- Engineering
- Source
- GitHub
Service desk
Route the finding to your service desk
Jira
Zendesk
- Freshdesk
Security operations
Send findings to security operations
Elastic
Datadog
- Webhooks
From source context to an owned finding, in the systems your team already uses.