Read/write access inventory
Map agents, sessions and identities to resources, distinguish reads from writes and surface permitted-versus-observed drift with explicit confidence.
Public roadmap
A sourced view of what exists, what public product pages already identify as next, and what remains exploratory. Priorities can change; shipped work is recorded in the changelog.
Shipped — Reserved for what the public changelog records. No public release has shipped yet, so this section is empty by design.
Built — publishes with the first release: done in the product today, and recorded as shipped in the changelog once that release exists.
Map agents, sessions and identities to resources, distinguish reads from writes and surface permitted-versus-observed drift with explicit confidence.
Version managed policy, gate tool calls deny-closed at the local hook and review policy against signals from read-only connectors.
Catalog servers, skills and tools, map who uses what and keep raw secrets out of managed configuration.
Attribute model spend and enforce budgets through deny-closed controls, while keeping model pricing explicitly declared.
Map activity to per-control status and sealed evidence across established framework families — evidence, never certification.
Deny governed actions at estate or agent scope, with instant engagement, dual-control recovery and an audited evidence pack.
Run the complete product in your environment without mandatory calls home; your estate and data remain under your control.
Work the existing product, trust or pricing pages already identify as the next step.
Move from today’s read-only graph of operator-declared rules to live federation against GA hyperscaler agent-identity registries.
Connect a real session source for sampling and an ordered history source for faithful sandbox replay.
Publish the first tagged artifacts with keyless signatures, SLSA provenance, SBOMs and OpenVEX evidence.
Publish final Pro and Business prices and open self-service checkout when commercial launch prerequisites are ready.
Directions under consideration, without a committed scope or date.
Post-v1 exploration of workflows for an organization’s own trained or hosted models; not available today.
A hosted, multi-tenant control plane remains planned as a separately priced offering; the current product is self-hosted.
SOC 2 Type II and ISO 27001 are planned; ISO 42001 remains readiness-mapped and not certified unless a formal engagement begins.
Extend the open connector ecosystem through the Apache-2.0 SDK while keeping every catalog row tied to source evidence.
Roadmap status describes direction. Shipped is reserved for what the public changelog records; Built means done in the product and publishing with the first release. Trust posture and current service availability remain separate factual surfaces.