A local-first Windows app that watches Claude Code, Codex, Cursor, Gemini CLI, and their child processes at the OS level - process activity, file changes, network connections - and gives you an honest audit trail. It doesn't ask an agent what it did. It watches independently.
Everything below is independent OS-level observation - not something an agent reports about itself, and not something you have to take on faith.
Every process an agent spawns, attributed back to it through a verified parent-chain walk - never guessed, and downgraded to "unknown" rather than assumed when the evidence runs out.
Create, modify, rename, and delete events inside the project folders you point it at - nothing outside them, and file contents are never read.
Which remote hosts an agent's processes actually talked to, named where possible using your own DNS cache rather than a guess - and clearly marked "Likely" when it is one.
An interactive relationship map - which agent touched which folder, app, or remote service - with confidence-coded lines, never a fabricated connection for something that wasn't actually observed.
Command lines are scanned for secret-shaped values (API keys, tokens) before anything is stored, logged, or shown - never after the fact.
Everything is stored in a local database on your own machine. Nothing leaves it unless you explicitly opt in to a specific integration (e.g. reading your own GitHub activity).
Three steps, no configuration required to get useful visibility.
Add the project folders you want visibility into. Nothing is watched outside them.
Claude Code, Codex, Cursor, and others are detected automatically as they run.
A live map, a daily summary, and a full audit trail - all computed from what was actually observed.
This project is pre-1.0 and says so plainly, including here.