Skip to main content

Platform / Operator Visibility

Day-2 control for agent actions

See decisions, approvals, budgets, and kill-switch state from the self-host kernel, plus Stage 2 control-plane ops (filters, metrics home, policy dry-run, webhook channels, optional OIDC).

Available nowshipping with ActantOSComing soonon the product roadmap

ActantOS operator view of governed agent sessions

Kernel foundation. Control plane shipped.

Stage 1 records every intercept, decision, and tool result in a hash-chained session timeline. Operators can export evidence, arm a kill switch, and enforce budgets without trusting prompt-only guardrails.

Stage 2 Agent Runtime Control Plane is done: session/decision filters, ops metrics home, policy dry-run, webhook approval channels, and optional OIDC for operator routes. Stage 3 isolation/WORM/SIEM remains future.

Available now (Stage 1 kernel)

Session event timeline

Available now

Hash-chained intercept, decision, and tool-result events per session for forensic review.

Kill switch & budgets

Available now

Deny-all kill switch and session budgets/rate limits enforced before execution; surfaced on ops metrics home.

Ops metrics home

Available now

Allow/deny/approval rates, kill-switch state, and budget remaining via /v1/metrics/usage ops_home.

List filters

Available now

Filter sessions and decisions by status, agent, outcome, risk, and session id.

Available now (Stage 2 control plane)

Policy dry-run

Available now

POST /v1/policy-bundles/:id/test evaluates without activating the bundle.

Webhook approval channel

Available now

Notify and decide approvals outside the web UI via webhook channel secret.

OIDC operator auth

Available now

Optional bearer tokens gate ops APIs while intercept stays fail-closed for agents.