Skip to content

Console

What a security team actually opens

The fleet view, ranked by risk, with the reasons attached. Every agent here is reachable: owner, purpose, permissions, dependencies, the decisions policy made on its behalf, and the incident if there was one.

This is a seeded demonstration fleet, not live customer data. The figures are fixed so the page reads the same for everyone — but the risk scores are summed from the factors shown on each agent, not typed in, because a score you cannot take apart is the thing this product argues against.

Fleet summary

6

Agents under governance

1

Unverified — discovered, not yet claimed

2

Missing a named owner

3

Scoring 65 or above

9

Actions refused or held

1

MCP servers that changed after approval

1

Contained right now

1

Open incidents

Underneath

Every agent runs as something

The fleet above is the visible layer. Each agent authenticates as a machine identity that holds the actual credential, and those identities outnumber the agents — they are also where the dormant accounts, the standing secrets and the shared credentials live.

7

Machine identities

4

Holding a long-lived secret

3

Missing an owner

283

Granted actions never used

Scoring

Ten dimensions, and every one has to say why

A risk score is only useful if it can be argued with. Each agent's score is the sum of its factors, and each factor names the dimension it came from.

Privilege

How much authority does it hold, and how much of it goes unused?

Data

How sensitive is what it can reach?

Action

Can it take irreversible action?

Tool

How dangerous are the tools it can call?

Model

Is the model approved, current and hosted where policy requires?

Dependency

What is it built on, and is any of it compromised?

Behaviour

How far has it drifted from its own baseline?

External exposure

Can it reach, or be reached from, outside the organization?

Incident history

Has it been involved in something before?

Compliance

Are its reviews, owners and certifications current?

Access

Who sees this console

An auditor reads evidence and cannot change what they are examining. A developer sees their own agents. Nobody gets the whole platform by default.

Organization Owner

Everything, including delegation of these roles.

Security Administrator

Policies, agents and incidents.

AI Governance Administrator

Agent approval, certification and compliance.

IAM Administrator

Identity, authentication and access.

Data Security Administrator

Classification, data policy and egress.

SOC Analyst

Monitoring, investigation and forensics.

Auditor

Read-only access to evidence. Cannot change what it examines.

Developer

Their own agents only.

Business Owner

The agents assigned to them.