mTLS between components
Mutual TLS on every internal hop; no plaintext control traffic.
● enforcedSelf-hosted · Vendor-neutral · Open-core
Context, resources, sessions and identities in one self-hosted plane: Claude Code at the deepest level, Codex and Grok Build alongside — and open to any other model or provider you run.
Your agents get what they need to do real work; you keep the granular permissions, policy, budgets and audit evidence to run all of it. It complements your agents; it does not compete.
The product tour
Every surface, with real console screenshots and an honest account of what is live today.
Read/write access and least-privilege drift — the differentiator.
Inspect observed session actions, models, tokens, costs, and event history, with governed work items and handoffs. Goals depend on the reporting source; computed task progress and the complete operating workflow are not yet verified.
One-click estate stop, dual-control recovery.
Control status and sealed evidence — not a certification.
See, attribute and govern model spend.
Real screenshot
17 genuine views of the Olivares console, captured from the product with example data.
Discover · 01 / 05
No proxy, no agents to babysit. Olivares watches your infrastructure and inventories every agent, session, model and MCP — with the surfaces each one reads and writes.
data-export-job holds an unreviewed write to prod-postgres — least-privilege drift, surfaced the moment it appears.
Govern · 02 / 05
Write policy as code and watch it land on the map. The unreviewed write to your production database becomes a denied, least-privilege path.
Pin the export job to read-only on the production database; block writes.
enforcement● enforcing
Cost · 03 / 05
Every dollar tied to the agent, model and team that caused it — with budgets and trends your finance team can act on, not guess at.
| Agent | Model | 30d | Trend | % total |
|---|---|---|---|---|
| claude-deploy-bot | claude-opus-4-8 | $1,860 | 22.1% | |
| data-export-job | magistral-small | $1,240 | 14.8% | |
| support-rag-agent | gpt-5.5 | $980 | 11.7% | |
| infra-copilot | claude-opus-4-8 | $880 | 10.5% | |
| billing-reconciler | claude-sonnet-4-6 | $720 | 8.6% | |
| qa-runner | gpt-5.4-mini | $180 | 2.1% | |
| +208 more agents | $2,540 | 30% | ||
Audit · 04 / 05
Every access in a tamper-evident, hash-chained ledger — filter it, replay it, and export it as evidence your auditors accept.
Security & Compliance · 05 / 05
mTLS, an append-only ledger and policy enforced at access time — mapped to the frameworks your auditors ask about.
Mutual TLS on every internal hop; no plaintext control traffic.
● enforcedEvery view and change hash-chained and tamper-evident.
● activePolicy enforced at access time — blocked, not just logged.
● enforcedPassive discovery from a minimally-privileged, read-only collector.
● active| Framework | Access control | Audit trail | Risk mgmt | Data governance | Coverage |
|---|---|---|---|---|---|
| EU AI Act | mapped | mapped | mapped | mapped | 96.9% |
| NIST AI RMF | mapped | mapped | mapped | partial | 98.6% |
| ISO 42001 | mapped | mapped | in progress | mapped | 97.4% |
| SOC 2 | mapped | mapped | partial | mapped | 98.4% |
How it works
A single container or binary on your own infrastructure. No account, no cloud dependency, no mandatory calls home.
Olivares AI passively finds every agent, session, MCP and model already running — no mandatory proxy.
It builds the access graph: what each agent can reach and what it actually touches, read versus read/write.
Set policy, watch for drift and export audit evidence. Visibility becomes control as your estate grows.
Open source
Olivares AI is open-core under AGPL-3.0. The complete product is in the public repository, tagged and signed since v26.8.0 — to run on your own infrastructure, inspect every line, and keep your data where it belongs. A commercial license and a dedicated enterprise tier are available when your organization needs them.
The complete product, self-hosted, free — no feature gates on the core.
Not tied to any single AI vendor, identity provider or cloud.
Olivares makes no mandatory calls home and runs in isolated, regulated networks. Fetching and updating the commercial add-ons needs an active subscription.
Sponsorship sustains the development, integration and updates of Olivares AI; it is not a support contract and buys no priority.
Deploy Olivares AI on your own infrastructure and get the access map your platform and security teams have been asking for.