Hosted · solo or team
Launching soonAgentTrail OS
Guardrails and a record for every agent you run. AgentTrail OS traces each session, finds the mistakes your agents repeat, proves a rule on your own history, then enforces it, for one developer or a whole team.
- Runs on
- Hosted by AgentTrail
- Setup
- One CLI command
- Built on
- OpenTelemetry GenAI
- Agents
- Claude Code and Cursor
How it works
Observe, detect, prove, enforce, watch
One loop, run on your own sessions. Each turn of it leaves you with a rule you have evidence for, instead of a post-mortem nobody reads again.
Observe
See what every agent did, and what it cost
Every agent session as OpenTelemetry traces: what the agent did, why it did it, and what it cost, searchable in seconds.
- Claude Code and Cursor in one command
- Any OTel agent via your collector
- Span-level detail
Detect
Find the mistakes your agents keep repeating
The pattern engine finds the repeats in your own sessions and suggests the rule, so a mistake gets caught the second time, not the tenth.
- Auto-detected repeats
- One click to a policy
- Capture and backtest in one move
Prove
Run a rule on your history before you turn it on
Replay a rule against your own recorded sessions, with zero model calls, and see what it would have caught. You enforce a rule once it is proven, not on a hunch.
- Counterfactual replay
- Your real sessions
- No model calls
Enforce
Block the bad action, or hold it, before it runs
Turn a proven rule on and each governed action is checked before it runs: warn, hold it for approval in the app, or block it outright. If the check cannot complete, the action does not proceed.
- Block, warn or hold
- Synced to every developer
- Fails closed
Watch
See what your guardrails catch
Every hold lands in one live record with the rule that fired, so you can see the guardrails working. A blocked call is recorded as a failed step, and becomes a violation you can search once content capture is on.
- Live approvals feed
- Before and after repeat rate per rule
- New patterns notify you
What you get
Everything in AgentTrail OS
Each card names the plan it starts on. Free is a real product for one developer, not a trial.
Sessions, turns and spans
Every planA session is one sitting with an agent, a turn is one thing you asked for, and a span is one action it took: the OpenTelemetry conversation, trace and span. Search and filter all of them.
What every session cost
Every planToken counts and cost are recorded with each session, so you can see what your agents spend, and on what.
Repeat failures, captured
Every planPatterns your agents repeat are detected from your own sessions and offered as policies you can adopt in one click.
74 curated policies
Every planKnown-bad patterns are covered from your first session, before any repeat: destructive SQL, leaked secrets, missing auth on new routes, weakened or deleted tests.
Your own policies
Every planWrite policies in the app. Owners and Admins author policies that apply across the workspace; on Business, personal policies can be scoped to one person.
Policy backtesting
Team+Prove a rule on your history before enforcing it: a replay over your recorded sessions shows what it would have caught.
Team-wide, synced enforcement
Team+Block, warn, or hold for in-app approval, with the same rules on every developer's machine. Decisions are made on AgentTrail's servers from your organization's policies.
Approval queue
Every planHeld actions wait in one queue in the app, each naming the rule that held it. Business adds SLA and median-resolve tracking.
Audit trail with export
Business+A record of what happened in your workspace that you can export, for the day a customer asks how you govern your AI agents.
Getting started
Connected in about five minutes
Once sign-up opens, there is no call to book first: create a workspace, connect your agent, and the repeat failures in your own history are waiting for you.
- 1
Create your workspace
Free for one developer. Add teammates when you move to Team.
- 2
Connect your agent
One command from the AgentTrail CLI. It connects one project at a time, so your workspace sees only the projects you chose.
$ npx -y @agenttrail/cli@latest setup --agent claude - 3
Turn your history into rules
Import your recent sessions and the repeat failures in them surface as suggested policies, alongside the curated library.
Which agents
- Claude Code
- Observability and enforcement.
- Cursor
- Observability and enforcement, with its own one-command setup. Enforcement on Cursor requires Cursor 3.21.16 or later.
- Any OpenTelemetry GenAI agent
- Sessions arrive through your own collector, for observability.
Hosted support for Codex, GitHub Copilot, Devin and Windsurf is coming. For Codex today, AgentTrail Guard runs locally.
Pricing
Plans, prices and the FAQ
Every plan, what it includes and what it costs is on the pricing page.
Security
Your agents' telemetry, not your codebase.
AgentTrail OS stores what your agents did so you can search it. Here is what that means, stated plainly.
- Export your data on every plan, Free included
- Deleted within 30 days of a request
- Every subprocessor named, with what it receives
- No certification claimed that we do not hold
- Stores
- Agent telemetry: actions, tool calls, timing, tokens, cost and policy decisions. It never needs access to your source repositories.
- Protects
- TLS 1.2+ for the web app and API, encrypted at rest, and each workspace's data kept separate by org-scoped keys.
- Training
- No cross-customer models trained on your traces without your explicit opt-in.
- Retention
- How far back you can see: 7 days on Free, 30 on Team, 90 on Business, custom on Enterprise. Older data is hidden, not deleted, until you ask us to delete it.
- Compliance
- We do not hold a SOC 2 report; an audit is planned but not started. SSO (SAML) and SCIM provisioning are planned and not yet available.
With AgentTrail Guard
AgentTrail Guard stops the mistake. AgentTrail OS remembers it.
Both block the same dangerous actions from the same open rule library. AgentTrail OS adds the record: every session searchable, repeats turned into rules, rules proven and shared across your team.
- 1
Protect yourself
AgentTrail Guard. Free, open source, on your machine.
- 2
Remember
A free AgentTrail OS account: every session searchable, repeat failures captured.
- 3
Protect the team
Team: enforcement synced to everyone, each rule backtested first.
- 4
Oversee
Business: response-time tracking on approvals, and an audit trail with export.
AgentTrail OS
See it on your own agents
Walk your team through AgentTrail OS with the people building it, and see how everyone's agent sessions become shared guardrails.
AgentTrail OS · For teams
Bring your team. We'll bring the demo.
A walkthrough for engineering teams rolling out AI agents: shared guardrails, approvals, and one record of every session your team runs.
Just you? Skip the call. Install AgentTrail Guard in two commands.