Hosted · solo or team

Launching soon

AgentTrail OS

Guardrails and a record for every agent you run. AgentTrail OS traces each session, finds the mistakes your agents repeat, proves a rule on your own history, then enforces it, for one developer or a whole team.

Works with

  • Claude Code
  • Cursor
Runs on
Hosted by AgentTrail
Setup
One CLI command
Built on
OpenTelemetry GenAI
Agents
Claude Code and Cursor

Observe, detect, prove, enforce, watch

One loop, run on your own sessions. Each turn of it leaves you with a rule you have evidence for, instead of a post-mortem nobody reads again.

  1. See what every agent did, and what it cost

    Every agent session as OpenTelemetry traces: what the agent did, why it did it, and what it cost, searchable in seconds.

    • Claude Code and Cursor in one command
    • Any OTel agent via your collector
    • Span-level detail
  2. Find the mistakes your agents keep repeating

    The pattern engine finds the repeats in your own sessions and suggests the rule, so a mistake gets caught the second time, not the tenth.

    • Auto-detected repeats
    • One click to a policy
    • Capture and backtest in one move
  3. Run a rule on your history before you turn it on

    Replay a rule against your own recorded sessions, with zero model calls, and see what it would have caught. You enforce a rule once it is proven, not on a hunch.

    • Counterfactual replay
    • Your real sessions
    • No model calls
  4. Block the bad action, or hold it, before it runs

    Turn a proven rule on and each governed action is checked before it runs: warn, hold it for approval in the app, or block it outright. If the check cannot complete, the action does not proceed.

    • Block, warn or hold
    • Synced to every developer
    • Fails closed
  5. See what your guardrails catch

    Every hold lands in one live record with the rule that fired, so you can see the guardrails working. A blocked call is recorded as a failed step, and becomes a violation you can search once content capture is on.

    • Live approvals feed
    • Before and after repeat rate per rule
    • New patterns notify you

Everything in AgentTrail OS

Each card names the plan it starts on. Free is a real product for one developer, not a trial.

  • Sessions, turns and spans

    Every plan

    A session is one sitting with an agent, a turn is one thing you asked for, and a span is one action it took: the OpenTelemetry conversation, trace and span. Search and filter all of them.

  • What every session cost

    Every plan

    Token counts and cost are recorded with each session, so you can see what your agents spend, and on what.

  • Repeat failures, captured

    Every plan

    Patterns your agents repeat are detected from your own sessions and offered as policies you can adopt in one click.

  • 74 curated policies

    Every plan

    Known-bad patterns are covered from your first session, before any repeat: destructive SQL, leaked secrets, missing auth on new routes, weakened or deleted tests.

  • Your own policies

    Every plan

    Write policies in the app. Owners and Admins author policies that apply across the workspace; on Business, personal policies can be scoped to one person.

  • Policy backtesting

    Team+

    Prove a rule on your history before enforcing it: a replay over your recorded sessions shows what it would have caught.

  • Team-wide, synced enforcement

    Team+

    Block, warn, or hold for in-app approval, with the same rules on every developer's machine. Decisions are made on AgentTrail's servers from your organization's policies.

  • Approval queue

    Every plan

    Held actions wait in one queue in the app, each naming the rule that held it. Business adds SLA and median-resolve tracking.

  • Audit trail with export

    Business+

    A record of what happened in your workspace that you can export, for the day a customer asks how you govern your AI agents.

Connected in about five minutes

Once sign-up opens, there is no call to book first: create a workspace, connect your agent, and the repeat failures in your own history are waiting for you.

  1. 1

    Create your workspace

    Free for one developer. Add teammates when you move to Team.

  2. 2

    Connect your agent

    One command from the AgentTrail CLI. It connects one project at a time, so your workspace sees only the projects you chose.

    $ npx -y @agenttrail/cli@latest setup --agent claude
  3. 3

    Turn your history into rules

    Import your recent sessions and the repeat failures in them surface as suggested policies, alongside the curated library.

Which agents

Claude Code
Observability and enforcement.
Cursor
Observability and enforcement, with its own one-command setup. Enforcement on Cursor requires Cursor 3.21.16 or later.
Any OpenTelemetry GenAI agent
Sessions arrive through your own collector, for observability.

Hosted support for Codex, GitHub Copilot, Devin and Windsurf is coming. For Codex today, AgentTrail Guard runs locally.

Plans, prices and the FAQ

Every plan, what it includes and what it costs is on the pricing page.

Your agents' telemetry, not your codebase.

AgentTrail OS stores what your agents did so you can search it. Here is what that means, stated plainly.

  • Export your data on every plan, Free included
  • Deleted within 30 days of a request
  • Every subprocessor named, with what it receives
  • No certification claimed that we do not hold
Stores
Agent telemetry: actions, tool calls, timing, tokens, cost and policy decisions. It never needs access to your source repositories.
Protects
TLS 1.2+ for the web app and API, encrypted at rest, and each workspace's data kept separate by org-scoped keys.
Training
No cross-customer models trained on your traces without your explicit opt-in.
Retention
How far back you can see: 7 days on Free, 30 on Team, 90 on Business, custom on Enterprise. Older data is hidden, not deleted, until you ask us to delete it.
Compliance
We do not hold a SOC 2 report; an audit is planned but not started. SSO (SAML) and SCIM provisioning are planned and not yet available.

AgentTrail Guard stops the mistake. AgentTrail OS remembers it.

Both block the same dangerous actions from the same open rule library. AgentTrail OS adds the record: every session searchable, repeats turned into rules, rules proven and shared across your team.

  1. 1

    Protect yourself

    AgentTrail Guard. Free, open source, on your machine.

  2. 2

    Remember

    A free AgentTrail OS account: every session searchable, repeat failures captured.

  3. 3

    Protect the team

    Team: enforcement synced to everyone, each rule backtested first.

  4. 4

    Oversee

    Business: response-time tracking on approvals, and an audit trail with export.

See it on your own agents

Walk your team through AgentTrail OS with the people building it, and see how everyone's agent sessions become shared guardrails.

Bring your team. We'll bring the demo.

A walkthrough for engineering teams rolling out AI agents: shared guardrails, approvals, and one record of every session your team runs.

Just you? Skip the call. Install AgentTrail Guard in two commands.

No sales pitch. Just a walkthrough.