Solutions · Security leadership

Say it once.
It holds
everywhere.

One set of controls, drawn from how your agents already work and applied to everything they reach. You confirm what matters. Backplanes enforces it, and records why.

Drafted from your own activity · One record per decision

mcp: connect issue-trackerAllowed
skill: bulk-exportWarned
mcp: connect file-transfer.externalBlocked

Every outcome, with the reason attached.

The question nobody owns

Identity governs who an agent is. The endpoint governs the machine. The application governs what it may call. Nobody owns whether the thing it just did was one you would have approved. That is the question you get asked, and it is the one your stack does not answer.

Start by knowing

See the whole organization before you commit to anything.

The observing half is free and arrives in a minute. It is also where your first controls come from, so what you approve is drawn from your own traffic rather than a template.

Every session across the organization, triaged by severity. The risks worth acting on first, with no new instrumentation.

Organization report

7-day window · generated now · organization-wide

Coverage · 7d28 of 32 people reporting · 88%

Top 3 things you should know7-day window

1
High

An MCP server nobody reviewed is in use in three sessions

What
file-transfer.external was connected from three sessions this week. It is not in the reviewed set, and nobody has ruled on it either way.
Why
A server outside the reviewed set can reach destinations the allowlist never saw. Unreviewed is not the same as unsafe, but it is not decided.
Consider
Decide, then enforce. Review the server once. Sanction it, or block it at the control layer, and the next session inherits the answer.

Session 73D9D2High2d ago

Release notes export + file hand-off

Sam's Codex · agent-trust

4 findings · $162.57 · 8h 14m

2
High

Agent reached an API endpoint outside the egress allowlist

What
A vendor-integration session made 12 outbound requests to api.example-vendor.com. The domain is not on the egress allowlist and was not reviewed.
Why
Off-allowlist destinations can carry credentials or customer data. Even a legitimate vendor should pass a check before traffic flows to it.
Consider
One decision, applied everywhere. Add the domain to the allowlist if vetted, or block it. Either way the decision belongs to the security team, not the agent.

Session B6F186High1d ago

Vendor webhook integration + signature verification

Maya's Codex · marketing-web

3 findings · $72.06 · 4h 47m

3
Medium

A skill from outside the catalog is now on six machines

What
bulk-export was first seen four days ago on one machine. It has since been loaded in sessions on six, none of them through the catalog.
Why
A skill that spreads by copy carries no verified build. What it does on the sixth machine may not be what it did on the first.
Consider
Pin it, or warn. Publish the catalog build and warn on anything else. Nothing is blocked until you say so.

Session 9F2E10Medium22h ago

Scanner platform v2 shipped to production

Alex's Claude · scanner-platform

6 findings · $483.60 · 9h 12m

Posture 3 indicatorsvs prior 7-day window

Sessions+4

24 this week

  • Prior 7d20
  • 90d baseline18 / week
  • Coverage88%

Highest severity2 high · 0 critical

High

  • High2
  • Medium7
  • Low5

Estimated spend+12%

$2,295 from token usage

  • Session 9F2E10$483.60
  • Session 73D9D2$162.57
  • Session B6F186$72.06

Findings 14 needing reviewAll severities · 7-day window

SeverityCategorySummaryAgentWhen
HighboundaryMCP server file-transfer.external connected, not in the reviewed setSam's Codex2d ago
HighboundaryOutbound request to non-allowlisted domain api.example-vendor.comMaya's Codex1d ago
MediumdriftSkill bulk-export loaded outside the catalog on 6 machinesAlex's Claude22h ago
Mediumbehaviorrm -rf executed on a directory outside the declared workspaceSam's Codex2d ago
MediumcomplianceCustomer email visible in transcript before redactionAlex's Claude22h ago
LowobservationSession exceeded 4h without a checkpointMaya's Codex3d ago
Rolled up from 24 sessions · Hosted analysisThis is a sample report
The external-access inventory: MCP servers, tools, skills and domains, each marked sanctioned, needs review, or blocked

And underneath

Everything your agents reached.

Every MCP server, tool, Skill and destination, and whether security signed off.

Explore the inventory
A Backplanes session report: verdict, time breakdown, findings, and the session story

And deeper still

Every number has an audit trail.

A verdict, the findings worth acting on, and the full story of each run.

See the full report

What it answers for you

A rule, applied, with a record.

Q1

What are our agents allowed to do, in a form I can state?

Controls you can read in one sitting, not several hundred toggles, drafted from your own agent activity. You confirm what matters.

Q2

How do I know it is applied, not just written down?

Every rule runs on the machines where agents work, in one of three modes. Start in monitor and read what it would have done.

Q3

What do I hand an auditor, or the board?

Every decision carries the revision that produced it, the outcome and the reason. To support compliance work. Not an audit opinion.

Not a second job

Capacity is the constraint, not budget.

Every security leader we have talked to already runs more tools than they have people. This one has to pay for itself in attention, not only in risk.

  • A minute to install. Nothing to configure.One command on the machines where agents run. No agent changes, no connectors to wire, and the first controls are drafted for you from what it sees.
  • The few things that matter, not the thousand that do not.Three things need a decision this week. The rest is sanctioned or unremarkable, and stays out of your inbox. No wall of alerts, no console to staff.
  • A budget that is not only yours.The same report reads as risk to you, as engineering to your leads, and as spend to finance. A tool three teams open is a tool three teams will help pay for.
I don’t want something that tells me I have more problems. I need something that helps me fix them.

CISO · global payments platform

Next

Start with your own traffic.

The first conversation is about what your agents already do, and the controls drafted from it. Not a demo environment.