
And underneath
Every number has an audit trail.
A verdict, the findings worth acting on, and the full story of each run.
See the full report →Solutions · Coding agents
Claude Code, Codex and Cursor arrived bottom-up, on laptops you do not manage, with your developers’ credentials and their own tools. That is a production deployment. Backplanes treats it as one.
18 proposals waiting
DraftsDrafted from what your agents did this week. None of them is live.
How this got classified wrong
Nobody filed a change request. A developer installed an agent, the agent installed an MCP server, and by week two it was writing code that ships. Every other production system here went through a review. This one went through a package install.
Start by knowing
One install, and every server, tool, skill and destination your coding agents reached is on one page, with who brought each one in. Claude Code, Codex and Cursor, with nothing to configure.
Every MCP server, tool, skill and destination your agents touched, and whether security signed off.
90-day observed window · generated now · organization-wide

And underneath
A verdict, the findings worth acting on, and the full story of each run.
See the full report →
And above
Every session across your org, triaged by severity. No new instrumentation.
Explore org reports →What it answers for you
Which coding agents are running here, and what did they bring?
Backplanes reads the sessions the agents already produce, so there is nothing to instrument. Back comes the inventory, with who brought each thing in.
What should they be allowed to do?
Start with the four rules below. Each is defensible in a technical evaluation today, not on a slide.
What happens the first time one tries something we did not approve?
Whatever you chose: monitor, warn or block. All three write the same record, so a week in monitor costs nothing.
In practice
Each one in the words a security team would use, with the moment it was tested and the reason behind the decision. All four are live.
Clearing what it read as a stale test environment, an agent runs terraform destroy.
Block
Blocked by "No destructive commands". The command matched a destructive pattern.
A session starts on a machine that is not reporting.
Warn
Flagged by "All sessions recorded". This machine has no session history.
An agent loads a skill that is not on the approved list.
Block
Blocked by "Approved tools only". This skill is not approved, and unlisted skills are set to block.
A plugin loads from a build that is not in the catalog.
Warn
Flagged by "Verified builds only". The local build does not match any approved build for this plugin.
Agents were coming in and the business didn’t know they were agents.
Former CISO · biopharmaceutical
What it does not do
Coding agents are the case Backplanes was built for first. That does not make the claim unlimited.
This list is maintained, not decorative. If something here is wrong or out of date, tell us.
Next
A week of real sessions is enough to see what your coding agents are reaching, and enough to argue about the first four rules with evidence in hand.