Platform

Know. Enforce.
Prove.

Backplanes shows you what your agents are doing across every tool, server and destination, enforces what you confirm, and records every decision. One policy across all agent activity, and nothing to configure.

Works with Claude Code, Codex and Cursor · SDK for the rest · Monitor, warn or block

Know1,240 sessions · 47 destinations · 3 worth a look
Enforcemcp: connect file-transfer.externalWarned
ProveWarned by Approved tools only · rev 4. Nobody in your org has approved this server.

Why this exists

Your controls ask whether an agent is allowed to act. Backplanes asks whether this action should happen. An agent can be fully authorized and still do something you would never have approved.

Anatomy of a decision

What a decision contains.

Allow, warn and block all produce the same record. Nobody has to reconstruct what happened from logs, and nobody has to take an engineer's word for it.

DecisionRecorded 14:22:07
agent tried: mcp: connect file-transfer.externalBlocked
Policy appliedApproved tools only · rev 4 · confirmed by the security team on 12 Aug
ContextCoding agent session · resolving MCP servers at session start
DecisionBlock. The connection never opened.
ExplanationBlocked by “Approved tools only”. This MCP server is not on the approved list, and unlisted servers are set to block.
EvidenceSession transcript · 1 matched rule · 0 exceptions applied

Where it sits

Published once. Decided locally, every time.

Your controls leave the dashboard once, as a signed bundle. Every decision after that is made on the machine.

Backplanes dashboard

Approved tools only · rev 4

Published 12 Aug by your security team.

The policy reaches machines once, as a signed bundle.

On every machine

mcp: connect file-transfer.externalBlocked

Decided here, by rev 4, without a call to us.

Installed with one command, or pushed through MDM.

Keeping up

Something changed. The rule is already drafted.

Backplanes drafts the rule and replays it against your real sessions. Nothing is live until you publish.

Proposeddrafted from last week

Warn on bulk-export

Skill · first seen 4 days ago · now on 6 machines

If this had been live for the last 30 days

14 sessions warned · 6 people · nothing blocked

Still a draft. Nothing enforces until you publish it.

How it works

Know first. Enforce when you are ready.

Backplanes drafts your first policy from how your agents already work, enforces what you confirm, and records every decision. As your agents change, it proposes what to control next.

Know

Know where you stand

Backplanes drafts the first policy from what your agents already do. You confirm what matters, and watch before anything changes.

What you know on day one →

Enforce

Apply it as agents act

Monitor, warn or block, across everything your agents reach. Deterministic code makes the call, never a model.

How enforcement works →

Backplanes keeps proposingAs your agents change, the next rule is already drafted.

Getting started

Three steps, and nothing is blocked yet.

  1. 01

    Your team installs it

    One command, no agent changes. Within a day you can see what your agents reach across the organization.

  2. 02

    Confirm the first controls, in monitor

    Backplanes drafts them from what it has seen. Monitor records what each would have done, and changes nothing.

  3. 03

    Enforce the ones you are sure about

    Read a day of real sessions, then move the rules you would defend to warn or block. Roll out to managed machines when you are ready.

curl -fsSL https://www.backplanes.com/spotlight/install.sh | sh

Next

See it against your own agents.

Point it at real activity. Within a day you know what your agents are doing, and what the first controls would do before any of them are live.