Intent-based visibility and control for AI agents

Know what’s happening. Decide what shouldn’t.

Backplanes drafts the controls from your own agent activity. Your security team hears about the few things that matter, not the thousand that do not.

Developers: install Backplanes free in a minute →

Know what’s happening

This week1,240 sessions
  • file-transfer.externalMCP servernew this week · 2 people
  • bulk-exportSkillspreading · now on 6 machines
  • paste.example.netDomainfirst seen · 1 session

Three need a decision. Everything else was fine.

Decide what shouldn’t

Proposed controlDraft

Backplanes proposes

block: file-transfer.external
WhyDrafted from this week. An MCP server nobody has approved was reached by 2 people.
If liveLast 30 days: 3 sessions blocked. Nothing else affected.
DecisionApprove as rev 5Monitor first

Your stack already answers

  • Authenticated?
  • Device managed?
  • Access to the system?
  • Tool approved?

It does not answer

Should this action happen, here, now?

An agent can clear every one of those and still do the thing you would have stopped.

How it works

Know first. Enforce when you are ready.

Backplanes drafts your first policy from how your agents already work, enforces what you confirm, and records every decision. As your agents change, it proposes what to control next.

Know

Know where you stand

Backplanes drafts the first policy from what your agents already do. You confirm what matters, and watch before anything changes.

What you know on day one →

Enforce

Apply it as agents act

Monitor, warn or block, across everything your agents reach. Deterministic code makes the call, never a model.

How enforcement works →

Backplanes keeps proposingAs your agents change, the next rule is already drafted.

Tell me what I don’t know. Because right now, nobody knows. There’s no visibility.

Former CISO · Enterprise Healthcare

Where the first draft comes from

Start by knowing where you stand.

Backplanes reads what your agents actually reach and drafts the first controls from it. Nothing is enforced until you say so.

Every MCP server, tool, skill and destination your agents touched, and whether security signed off.

External access

90-day observed window · generated now · organization-wide

External domains
47
MCP servers
12
MCP tools
31
Skills
9
Needs review
3
All 99MCP servers 12MCP tools 31Skills 9Plugins 4External domains 47Needs review 3Blocked 1
ResourceKindStatusSessionsCallsReached byLast
github.comdomain · git + api.github.comDomainSanctioned412,890team12m
web-searchmcp_server:web-searchMCP serverSanctioned221,2046 engineers1h
api.stripe.comdomain · paymentsDomainSanctioned14312alex, maya2h
api.example-vendor.comdomain · not on allowlistDomainNeeds review347maya2d
filesystemmcp_server:filesystemMCP serverSanctioned186425 engineers3h
pdf-exportskill:pdf-exportSkillSanctioned753alex1d
browser_navigatemcp_tool:playwright/browser_navigateMCP toolUnreviewed18260maya4h
unknown-cdn.iodomain · first seen this weekDomainBlocked12sam3d
A Backplanes session report: verdict, time breakdown, findings, and the session story

And underneath

Every number has an audit trail.

A verdict, the findings worth acting on, and the full story of each run.

See the full report
Org report, Security view: top risks and a severity-triaged findings table

And above

Rolled up for the org.

Every session across your org, triaged by severity. No new instrumentation.

Explore org reports

In practice

The type of things you can ask for today.

Each one in the words a security team would use, with the moment it was tested and the reason behind the decision. All four are live.

Nothing destructive runs, whatever the agent thought it was doing.

Context

Clearing what it read as a stale test environment, an agent runs terraform destroy.

Decision

Block

Reason

Blocked by "No destructive commands". The command matched a destructive pattern.

Every agent session is on the record.

Context

A session starts on a machine that is not reporting.

Decision

Warn

Reason

Flagged by "All sessions recorded". This machine has no session history.

Our people use the MCP servers and skills we approved, not whatever they found.

Context

An agent loads a skill that is not on the approved list.

Decision

Block

Reason

Blocked by "Approved tools only". This skill is not approved, and unlisted skills are set to block.

Plugins run only from the builds we verified.

Context

A plugin loads from a build that is not in the catalog.

Decision

Warn

Reason

Flagged by "Verified builds only". The local build does not match any approved build for this plugin.

Rolling it out

One command. Then you know what’s happening across your org.

  1. 01

    Your team installs Backplanes.

    $ curl -fsSL https://www.backplanes.com/spotlight/install.sh | sh

    Works with macOS, Linux, and WSL 2.

    Each engineer authenticates in the browser and joins the team account; their sessions start capturing as they finish. No agent changes, no admin rollout to schedule.

  2. 02

    Know what’s happening across the org.

    Auto-captureLive
    • 11:08 AMSession ended migrate-pg-v14Ready
    Org report · this week38 people
    • 1,240sessions
    • 12MCP servers
    • 31tools
    • 47destinations
    Worth a look3Everything else was fine.

    Sessions capture themselves when they end, redacted locally before anything leaves the laptop. They roll up into the org report: every agent, tool, server and destination in use across your organization, and the few things worth a look. Nobody on the team does anything.

    No OAuth into Anthropic or OpenAI. The CLI only reads sessions after they end.

  3. 03

    Decide what shouldn’t. Your first policy is drafted.

    First policyDraft
    • Blockfile-transfer.externalMCP server nobody approved · reached by 2 people
    • Warnbulk-exportSkill spreading fast · now on 6 machines
    • Monitorpaste.example.netDomain first seen this week · 1 session
    Nothing enforces until you approve it.

    Backplanes drafts the first policy from what it saw: the tools worth approving, the destinations worth watching, the moves worth stopping. You confirm what matters, or run it in monitor first and read what it would have done. Each engineer still gets their own session reports from day one.

Coverage

What Backplanes covers.

The harnesses your team already uses, everything an agent can reach through them, and every posture a control can take.

  • Claude Code, Codex and CursorToday, with no setup. Anything you build yourself reports through the Python SDK.
  • MCP servers and toolsIndividually governable, not just per server
  • Skills and pluginsIncluding which specific build is running
  • CommandsMatched after normalization, not by raw string
  • External domainsEvery destination your agents reach
  • Monitor, warn and blockPlus the default for anything unlisted

Controls written in plain language. State the outcome in a sentence, confirm what Backplanes derived from it, and see what it would have done before it enforces anything.

We earn the trust we ask for.

Narrow access.
Useful reports.

  • No agent OAuthBackplanes never touches your Anthropic or OpenAI accounts.
  • Completed sessions onlyBackplanes reads sessions after they end. It does not sit in the middle of your agent run.
  • Defense in depthPII and credentials are scrubbed locally before upload. A second pass runs server-side before storage.
  • Zero retention at the LLM layerContractual, for every provider we use.

Read more about trust →

Built by people who’ve been on the other side of this.

Built by leaders and practitioners from
Backed by

Pricing

Get started for free with your team.

Rolling Backplanes out across an org, with attribution, volume, or specific controls? Talk to us and we’ll set it up together. For individual developers and the teams they work on, session reports are free: no seats to count, no trial clock.

$ curl -fsSL https://www.backplanes.com/spotlight/install.sh | sh

Works with macOS, Linux, and WSL 2.

Your agents are already working.

The question is whether anyone in your organization could say what they were allowed to do, and prove it.

Or start where your engineers already are: install Backplanes →

Get in touch

hello@backplanes.comJoin our Slack