Discovery & inventory
Automatically discover and catalog every agent, session, MCP server, skill and model running across your infrastructure — multi-host and multi-cloud, with no proxy to babysit.
Product
Olivares AI brings every part of your enterprise AI under one roof — the models and agents, the MCP servers and identities behind them, the data they touch and the budgets they spend. See what each can reach, decide what it can do, and prove it — built around Claude, on your own infrastructure.
The access map · the differentiator
Every edge carries an access mode taken from your infrastructure’s own records — whether an agent only reads a resource, or can also write to it. Write is where the risk is.
Permitted is what policy allows; observed is what the collector actually saw. The gap between them is least-privilege drift — an observed write nobody allowed is the headline finding.
Confidence is shown, never faked. When activity can’t be tied to a specific agent, attribution collapses honestly to the credential and is marked approximate — we never invent an agent.
The product tour
Every surface, with real console screenshots and an honest account of what is live today.
Read/write access and least-privilege drift — the differentiator.
Author managed policy, version it, deny-closed at the hook.
Catalog every tool; declared annotations, never trusted as truth.
A dedicated identity per agent, federated to your IdP.
See, attribute and govern model spend.
Control status and sealed evidence — not a certification.
Where agent quality gets measured and gated.
One-click estate stop, dual-control recovery.
Product demo
A silent, self-hosted tour of the product surfaces — real rendered assets and console captures, with no third-party embed or tracking.
Recorded pre-release — counts shown on screen reflect an earlier snapshot.
This video is silent and uses on-screen captions. The ~56-second transcript below reproduces the rendered technical text in English.
Ground truth for enterprise AI.
OLIVARES AI
Integrate, manage and secure AI in your enterprise
built around Claude and Claude Code
It complements Claude — it doesn't compete. Self-hosted, on your infrastructure.
Models. Agents. MCP. Identities. Data. Policies. Budgets. Evidence.
One self-hosted binary. Your governance data stays in infrastructure you control.
See what your AI touches
A read/write access map — Permitted vs Observed, and the drift between them.
kernel · pgAudit · CloudTrail · MCP
Decide what it can do
Deny-closed enforcement at the point of action — the unauthorized doesn't execute.
4 enforcement points · Cedar authz
Built around Claude
Govern Claude Code in the hook; operate governed sessions; manage MCP and A2A.
Claude Code · MCP · A2A
Human & non-human identity
WebAuthn, PIV/CAC and AAL step-up for people; lifecycle and federation for the agents behind them.
Entra · Okta · SPIFFE · SCIM
Protect the data
Guardrails, DLP, BYOK encryption and OS-isolated sandboxes — what isn't stored can't leak.
BYOK · DLP · gVisor / Firecracker · PQ-TLS
Prove it
A hash-chained, signed audit ledger and sealed evidence for the frameworks auditors ask for.
26 framework catalogs · signed ledger
Run it on a budget
FinOps budgets that don't just alert — they deny or throttle spend.
budgets that act · cost-per-outcome
Keep it safe
Calibrated LLM-judge evals with a blocking CI gate, and a red-team battery that runs only in the sandbox.
calibrated judge · red-team
Stay in control
Live sessions, the orchestration graph, and a one-click estate kill-switch that fails closed.
estate kill-switch · fails closed
WHAT'S INSIDE
29 · 157 · 26 · 4
wired modules / connector directories / framework catalogs / enforcement points
One engine, one console, one binary — honest about what's live and what's pre-1.0.
Self-hosted. Your infrastructure. Even air-gapped.
open-source, data stays in your boundary
Ground truth for enterprise AI.
Open-source · github.com/olivaresai/olivares · olivares.ai
One self-hosted product
Olivares AI is a single self-hosted product. The access map is the spine; around it sit the capabilities a platform, security or FinOps team needs to run an AI estate — the full scope the complete product targets, grouped here by what they help you do.
See your whole AI estate.
Automatically discover and catalog every agent, session, MCP server, skill and model running across your infrastructure — multi-host and multi-cloud, with no proxy to babysit.
See in real time what each agent is doing — its goal, its tasks, its progress and its live cost — alongside a full historical timeline.
Track the health, uptime and SLAs of your agents and MCP servers, with alerts on outages or degradation and a live dependency map.
Govern who — and what — is allowed to act.
Granular control over who and what can act — role- and attribute-based access, per-agent identity, human-in-the-loop approvals and a policy engine — with every action traceable to a person.
See and govern how agents coordinate — delegation, multi-agent workflows and scheduled or event-driven agents — visualised end to end.
Curate and reuse approved agents, MCPs and skills as versioned company templates, with governed self-service.
Secure and auditable by design.
Tamper-evident audit, secrets and egress controls, and guardrails against prompt injection, jailbreaks and data leaks — with reconstructable incident forensics.
Probe your agents safely — adversarial prompt-injection, jailbreak and exfiltration tests, scored against the OWASP agentic-risk checklist.
Test agents on synthetic data and replay sessions in an isolated sandbox before they ever touch production.
Govern the whole stack, control the spend.
Govern your entire AI stack, not just one vendor — routing, selection, fallback and versioning across hosted and local inference, with centralised key governance.
Track AI spend by team, agent, model and project, set budgets and alerts, and forecast — with routing and caching policy to manage spend.
Answer the question that matters — is my agent still doing the right thing? — with evals, regression testing, output-quality monitoring and drift detection.
Govern what your agents know.
Govern what your agents know and retrieve — knowledge bases and RAG, governed retrieval, data lineage and residency, versioned prompts and persistent memory.
Open the enterprise door.
Map your AI program to the frameworks enterprises ask about — the EU AI Act, NIST AI RMF, ISO 42001, SOC 2 / ISO 27001 and GDPR — with exportable audit evidence and agent risk classification. It helps you demonstrate controls; it does not grant a certification.
Operate the platform itself.
Govern your agents’ tools — a catalog of MCP servers, skills and plugins, what is connected to whom, configuration, versioning and health.
Govern the agent and MCP lifecycle — provision, update and retire — and wire them into your real network, servers and data stores, with versioning, rollback and GitOps. Direct actuation is governed and deny-closed: live for a subset today, provisioned on-demand for the rest.
Olivares talks to the tools you already run — chat, on-call, your SIEM, ITSM systems, developer portals, webhooks and email.
Manage Olivares itself as code — a full API, a Terraform provider, a declarative CLI and event webhooks.
Organization hierarchy and delegated administration for service providers and large enterprises, with real tenant isolation and per-org usage.
High-level views for leadership — KPIs across cost, usage, risk and compliance, with scheduled, exportable reports.
Manage conversational and realtime voice agents — sessions, state, transcription, latency and governance.
On the roadmap · post-v1
Managing an organization’s own trained or hosted models — a private model registry and fine-tuning workflows — is planned for after the first release. We are not presenting it as available today.
Deploy Olivares AI on your own infrastructure and get the access map your platform and security teams have been asking for.