
And underneath
Every number has an audit trail.
A verdict, the findings worth acting on, and the full story of each run.
See the full report →Solutions · MCP and tool governance
Finding them is the easy half, and most tools stop there. Backplanes turns the inventory into a decision: which servers, tools and skills your agents may use, enforced where they run.
Backplanes proposes
The easy half
An MCP server installs in seconds from a config file, with nobody asked. By the time security hears about it, it is already in production work. Scanning tells you they are there. It does not tell you whether they should be.
Start by knowing
Backplanes does not ask you to imagine which servers your organization needs. It starts from the ones your agents already use, across Claude Code, Codex and Cursor.
Every MCP server your agents connected to, and whether anyone has signed off on it.
90-day observed window · generated now · MCP servers, organization-wide

And underneath
A verdict, the findings worth acting on, and the full story of each run.
See the full report →
And above
Every session across your org, triaged by severity. No new instrumentation.
Explore org reports →What it answers for you
What is installed, across everyone?
Every server, tool, Skill, plugin and domain your agents reached, built from the sessions they already produce. Each row names who brought it in.
What may be used, and at what granularity?
Per resource kind, each with its own default for anything unlisted. That one setting decides allowlist or watchlist.
How does it apply on a machine I do not manage?
The rules travel as a signed document the engine verifies and evaluates locally. A catalog outage cannot stop a decision.
The review queue
Nothing nobody has ruled on is quietly allowed. It lands as unreviewed, and you work through the queue.
Filter · needs review & blocked
I spend half my time just struggling to understand our subprocessor chain. What does Slack use? What did they add while I wasn’t looking?
Security Engineer
What it does not do
The part a security engineer will test first.
web-search approves a string a config file claims is web-search. That is vendor management, not attestation, and we would rather say so than let you assume otherwise.This list is maintained, not decorative. If something here is wrong or out of date, tell us.
Next
See what your agents reached, then tell us which of it should have been allowed.