Solutions · Coding agents

The rollout nobody approved.

Claude Code, Codex and Cursor arrived bottom-up, on laptops you do not manage, with your developers’ credentials and their own tools. That is a production deployment. Backplanes treats it as one.

Claude Code, Codex and Cursor · SDK for the rest · Free to start

18 proposals waiting

Drafts
  • file-transfer.externalMCP server2 people
  • bulk-exportSkill6 people
  • paste.example.netDomain1 person
  • and 15 more

Drafted from what your agents did this week. None of them is live.

How this got classified wrong

Nobody filed a change request. A developer installed an agent, the agent installed an MCP server, and by week two it was writing code that ships. Every other production system here went through a review. This one went through a package install.

Start by knowing

See what they brought in before you rule on any of it.

One install, and every server, tool, skill and destination your coding agents reached is on one page, with who brought each one in. Claude Code, Codex and Cursor, with nothing to configure.

Every MCP server, tool, skill and destination your agents touched, and whether security signed off.

External access

90-day observed window · generated now · organization-wide

External domains
47
MCP servers
12
MCP tools
31
Skills
9
Needs review
3
All 99MCP servers 12MCP tools 31Skills 9Plugins 4External domains 47Needs review 3Blocked 1
ResourceKindStatusSessionsCallsReached byLast
github.comdomain · git + api.github.comDomainSanctioned412,890team12m
web-searchmcp_server:web-searchMCP serverSanctioned221,2046 engineers1h
api.stripe.comdomain · paymentsDomainSanctioned14312alex, maya2h
api.example-vendor.comdomain · not on allowlistDomainNeeds review347maya2d
filesystemmcp_server:filesystemMCP serverSanctioned186425 engineers3h
pdf-exportskill:pdf-exportSkillSanctioned753alex1d
browser_navigatemcp_tool:playwright/browser_navigateMCP toolUnreviewed18260maya4h
unknown-cdn.iodomain · first seen this weekDomainBlocked12sam3d
A Backplanes session report: verdict, time breakdown, findings, and the session story

And underneath

Every number has an audit trail.

A verdict, the findings worth acting on, and the full story of each run.

See the full report
Org report, Security view: top risks and a severity-triaged findings table

And above

Rolled up for the org.

Every session across your org, triaged by severity. No new instrumentation.

Explore org reports

What it answers for you

Find them, decide, hold the line.

Q1

Which coding agents are running here, and what did they bring?

Backplanes reads the sessions the agents already produce, so there is nothing to instrument. Back comes the inventory, with who brought each thing in.

Q2

What should they be allowed to do?

Start with the four rules below. Each is defensible in a technical evaluation today, not on a slide.

Q3

What happens the first time one tries something we did not approve?

Whatever you chose: monitor, warn or block. All three write the same record, so a week in monitor costs nothing.

In practice

The type of things you can ask for today.

Each one in the words a security team would use, with the moment it was tested and the reason behind the decision. All four are live.

Nothing destructive runs, whatever the agent thought it was doing.

Context

Clearing what it read as a stale test environment, an agent runs terraform destroy.

Decision

Block

Reason

Blocked by "No destructive commands". The command matched a destructive pattern.

Every agent session is on the record.

Context

A session starts on a machine that is not reporting.

Decision

Warn

Reason

Flagged by "All sessions recorded". This machine has no session history.

Our people use the MCP servers and skills we approved, not whatever they found.

Context

An agent loads a skill that is not on the approved list.

Decision

Block

Reason

Blocked by "Approved tools only". This skill is not approved, and unlisted skills are set to block.

Plugins run only from the builds we verified.

Context

A plugin loads from a build that is not in the catalog.

Decision

Warn

Reason

Flagged by "Verified builds only". The local build does not match any approved build for this plugin.

Agents were coming in and the business didn’t know they were agents.

Former CISO · biopharmaceutical

What it does not do

Where the coverage stops.

Coding agents are the case Backplanes was built for first. That does not make the claim unlimited.

Coverage is per harness, not universal.
An agent Backplanes is not installed alongside produces no sessions and cannot be governed. Claude Code, Codex and Cursor report today, anything you build yourself reports through the Python SDK, and a harness not on that list is a conversation rather than a limit.
There is no production-versus-development condition.
The environment signal does not reach the enforcement hook, so “not against production” is not expressible. What is expressible is what may be run at all.
One agent calling another is not governed.
Backplanes governs what an agent reaches: servers, tools, skills, plugins, domains and commands. It does not arbitrate one agent handing work to another.

This list is maintained, not decorative. If something here is wrong or out of date, tell us.

Next

Point it at one team first.

A week of real sessions is enough to see what your coding agents are reaching, and enough to argue about the first four rules with evidence in hand.