See what your AI agents
actually do on your computer.

A local-first Windows app that watches Claude Code, Codex, Cursor, Gemini CLI, and their child processes at the OS level - process activity, file changes, network connections - and gives you an honest audit trail. It doesn't ask an agent what it did. It watches independently.

Early development - Windows only, monitor-only (no automatic blocking yet)

What it actually watches

Everything below is independent OS-level observation - not something an agent reports about itself, and not something you have to take on faith.

Process activity

Every process an agent spawns, attributed back to it through a verified parent-chain walk - never guessed, and downgraded to "unknown" rather than assumed when the evidence runs out.

File changes

Create, modify, rename, and delete events inside the project folders you point it at - nothing outside them, and file contents are never read.

Network connections

Which remote hosts an agent's processes actually talked to, named where possible using your own DNS cache rather than a guess - and clearly marked "Likely" when it is one.

A real map of what happened

An interactive relationship map - which agent touched which folder, app, or remote service - with confidence-coded lines, never a fabricated connection for something that wasn't actually observed.

Redaction built in

Command lines are scanned for secret-shaped values (API keys, tokens) before anything is stored, logged, or shown - never after the fact.

Local-first, no telemetry

Everything is stored in a local database on your own machine. Nothing leaves it unless you explicitly opt in to a specific integration (e.g. reading your own GitHub activity).

How it works

Three steps, no configuration required to get useful visibility.

Install and point it at a folder

Add the project folders you want visibility into. Nothing is watched outside them.

Work with your agents as usual

Claude Code, Codex, Cursor, and others are detected automatically as they run.

See exactly what happened

A live map, a daily summary, and a full audit trail - all computed from what was actually observed.

What it doesn't do (yet)

This project is pre-1.0 and says so plainly, including here.