Skip to content

The firm’s AI agents, on the record.

AI agents put themselves on the register, down to the one running quietly on a single laptop. Each ties back to a named person, and each has an off switch.

Agent governance

Agents

Every individual agent on the register, recorded from its own traffic the moment it first appears. Each row is one agent with one owner, one home, and its own controls.

agents
9
owners
8
products
5
blocked
1
Claude Code2 agentsProduct view
Claude Code · ws-9f31c2abDelegated
Devon Okafor · ws-9f31c2ab · observed on the wire
64exchanges
143actions
161ktokens
seen Jun 17, 04:42 PM
Claude Code · ws-4e88d1f0Delegated
Priya Raghavan · ws-4e88d1f0 · observed on the wire
31exchanges
62actions
71ktokens
seen Jun 17, 11:26 AM
Codex CLI1 agentProduct view
Codex CLI · ws-b3e7a950Delegated
Tom Baxter · ws-b3e7a950 · observed on the wire
18exchanges
26actions
48ktokens
seen Jun 16, 03:19 PM
Cursor1 agentProduct view
Cursor · ws-7b19f3c4Delegated
Avery Chen · ws-7b19f3c4 · observed on the wire
42exchanges
60actions
76ktokens
seen Jun 17, 06:03 PM
Custom API client4 agentsProduct view
Trade reconciliation runnerMachine
Marcus Webb · ws-a7d20e13 · observed on the wire · runs scheduled
84exchanges
59actions
105ktokens
seen Jun 18, 02:10 AM
Client support drafterMachine
Hannah Brooks · ws-30c9e6f2 · observed on the wire · runs service
57exchanges
39actions
91ktokens
seen Jun 17, 05:25 PM
Custom API client · ws-51b6aa02BlockedMachine
Nathan Cole · ws-51b6aa02 · observed on the wire
28exchanges
14actions
25ktokens
seen Jun 10, 03:47 PM
Custom API client · ws-0d44b9e6Identity unknown
no owner on record · ws-0d44b9e6 · observed on the wire
12exchanges
6actions
9.6ktokens
seen Jun 16, 10:04 PM
Gemini CLI1 agentProduct view
Gemini CLI · ws-e5c20b98DelegatedDormant
Kenji Sato · ws-e5c20b98 · observed on the wire
9exchanges
14actions
14ktokens
seen May 24, 11:20 AM
Window May 19, 2026 to Jun 18, 2026. Liveness and identity come from the durable register; counts are window bounded. Every record is content free.
Needs a look4 to review

How Agent Governance works with Proxara.

An employee hands an agent a task and walks away. The agent drifts out of its lane. Here is what happens next.

Agentsfenwick-ridge
← agent register
Claude Code · fenwick-repodelegatedallowedMRMaya R.owner
first seen Tue, on Maya's MacBook, delegated identity
Routinelearned scope
crm.search
crm.export
repo read/write
Todaywhat it just did
crm.export×14
payroll.readfirst time out of scope
Controls
ObserveRestrictBlockStop now
Recent
mcp payroll.readoutside routine2:47 PM
mcp crm.exportcall 272:46 PM
What it is allowed to reach, next to what it just did

Everything in the film is the product: the register, what each agent can reach, the hold, and Rox.

Every agent has an owner and an off switch.

Open any row and the register goes one level deeper: who is accountable, what the agent is allowed to reach, and the controls to slow it, hold it, or stop it outright.

One Claude Code agent, shown exactly as it appears in the console.

Agents
Agent governance

Claude Code · ws-9f31c2ab

Observed and recorded on every covered device.

Allowed
Controls
Observe is the silent default. Every exchange and action is recorded on the ledger; nothing is held.
Stop now records a one-shot request. After the device pulls it, the request is evaluated when this agent next makes a governed request. Only a process freshly matched to this agent can be terminated.
Retiring ends this agent's lifecycle: the record and its history stay on the register for the audit trail, marked retired.
Exchanges
64
Sessions
12
Actions
143
Tokens, measured
161k
Cost
$3.1
Birth record
First seen
Apr 22, 10:14 AM
Provenance
Observed on the wire
Created by
Where it lives
ws-9f31c2ab on NB-MBP-014
Execution context
interactive
Identity
Delegated. Acts with a person's own sign-in. Credential shape: Authorization code (user sign-in).
Scope map
Routine tools
Read412 uses
Edit388 uses
Bash344 uses
Grep201 uses
Write126 uses
WebFetch44 uses
Routine servers
github61 calls
postgres20 calls
AI destinations
Claude236 exchanges
Data classes touchedAccount numbersClient PII
Sessions (12)
Devon Okafor
claude-opus-4-8 · device NB-MBP-014
11 exchanges
26 actions
Jun 17, 01:05 PM → Jun 17, 04:42 PM
Devon Okafor
claude-opus-4-8 · device NB-MBP-014
8 exchanges
19 actions
Jun 16, 10:12 AM → Jun 16, 12:31 PM
Devon Okafor
claude-opus-4-8 · device NB-MBP-014
9 exchanges
22 actions
Jun 13, 02:22 PM → Jun 13, 05:48 PM
Devon Okafor
claude-opus-4-8 · device NB-MBP-014
6 exchanges
13 actions
Jun 11, 09:36 AM → Jun 11, 11:04 AM
Showing the 4 most recent of 12 sessions.
Action timeline (6 recent)
EditTool call
3 argument names · 1.8 KB sent · 96 B returned
Jun 17, 04:41 PM
session 97d3a6e8 · turn 3 · claude-opus-4-8
create_pull_requestMCP tool callgithub
5 argument names · 1.2 KB sent · 486 B returned
Jun 17, 03:38 PM
session 97d3a6e8 · turn 2 · claude-opus-4-8
GrepTool call
2 argument names · 64 B sent · 4.8 KB returned
Jun 17, 02:55 PM
session 97d3a6e8 · turn 2 · claude-opus-4-8
ReadTool call
1 argument name · 78 B sent · 18.0 KB returned · 2 data classes sealed (Account numbers, Client PII)
Jun 17, 01:07 PM
session 97d3a6e8 · turn 1 · claude-opus-4-8
queryMCP tool callpostgres
1 argument name · 342 B sent · 11.9 KB returned · 1 data class sealed (Account numbers)
Jun 16, 11:47 AM
session c2b8f5a1 · turn 4 · claude-opus-4-8
search_filesMCP tool callgoogle-drive
1 argument name · 88 B sent · 2.3 KB returned
Jun 15, 09:14 AM
session a154e097 · turn 1 · claude-opus-4-8
Action records are content free: tool names, argument key names, byte sizes, and detected data classes. Values never leave the device record.
Cost
$3.1in this window
claude-opus-4-864 exchanges148k in / 12k out$3.1
Framework controls cited
SEC Regulation S-P (Safeguards)1 control · 9 citations
FINRA Rule 3110 (Supervision)1 control · 4 citations
Signed extract

Everything recorded for this agent traces back to envelopes the device signed before they left the machine. The extract bundles those envelopes with the device keys, Merkle proofs, signed anchors, and a verifier that runs offline. An examiner can check it without access to Proxara.

What Proxara covers, and where it stops.

Every mark below is something the product does today, not a plan. Where coverage has a limit, the row says so.

SurfaceOn the registerRedacted in transitBlock & limitResearched
Tools connected inside managed AI appsEvery tool in these apps is found on install and lands on the register. The ones running on the laptop itself are blocked or warned by policy.
Cloud connectorsThe firm’s own systems connect through Proxara Connect, governed end to end wherever the person signs in. Other connectors in Claude’s directory are seen by name, and the firm can turn them off in Claude’s own admin.
Coding agents on the command lineTheir settings are read and listed, never rewritten. The agents themselves sit on the register, where they can be limited, blocked, or stopped.
Beyond the deviceother makers’ cloud add-ons, and machines without ProxaraCloud add-ons from other AI makers, and machines Proxara was never installed on. Named plainly rather than implied.

New servers get researched, not just listed.

The moment a server the firm has not approved appears on a device, Rox researches it: real sources, written reasoning, and a call to allow, watch, or block.

  • A risk rating of low, medium, or high, with the reasoning written out.
  • Links to real sources, so the call can be checked.
  • One click to block, and the block reaches every covered device.
  • If the firm chooses, a bad verdict holds the server automatically.

One page a board can read.

Which agents are running, who owns each one, what they touched, and that all of it was governed. Signed, so it holds up outside the room it was written in.

The person responsible walks in with an account of the firm’s agents, not a promise about them.

Book a demo

A one-page summary a board receives.

Put every agent on the record.

Tell us what the firm runs, and a person will reply in a few hours.

Talk to us