Agentic Control Plane

Permissions, approvals, and cost for the coding agents you run.

See and control every action your agents take. Every call is checked before it runs and priced after. One command, no code changes. Free for individuals.

$ curl -sf https://agenticcontrolplane.com/install.sh | bash

Audit mode first: recorded, not blocked. --local keeps everything on your machine. What is stored, exactly →

$git push --force origin main
verdictDENIED
ruleprotected-branch · logged ~/.acp/audit.jsonl
Our own coding agent, mid-session. Some actions are off-limits: not even an approval click reaches them.
More real interceptions, all ours →
1,223,714
policy decisions, most of them on our own agents, and counting
45/48 control scenarios passed in AgentGovBench, our own published benchmark, vs 13/48 for the harness alone · scorecard →

Control your fleet of AI agents

Claude Code in one terminal, Codex in another, an agent running overnight, each holding dozens of tools it never told you about: a real Claude Code session declares 75. ACP lists every tool on the first call and makes each one a click: allow, ask me, or never. Dropping the prod database, force-pushing over main, a token going out in a curl: on the never list once, for every agent.

How the rules work: allow, ask, never, and who decides →
ACP activity log filtered to denied calls: one row per blocked call with the time, tool, reason, decision, and the agent identity that tried it. Rows include Bash.rm blocked as 'Delete files' with the note 'deleted files don't come back', a blocked edit of ACP's own configuration, and curl calls blocked because the hook cannot see what runs inside them.

Every blocked call is a row: the tool, the reason, and the agent that tried it. Shown: denials on our own agents. Tap to enlarge.

Use it for your own work, for free

One command on your machine and every run gets a record: each tool call and model call in order, what it touched, what it cost, and the decision that let it through. When a run does something you didn't expect, or costs $50 you didn't expect, you can see exactly why. Free up to 5 agents; add --local and there is no account at all.

What you get on your own machine, in detail →
ACP session trace for one Claude Code run: a timeline strip of every call, then each call in order with its time, tool, decision, latency, and cost (model calls with tokens and cents, Bash.ls and Bash.cd allowed). One call is open on the right showing the decision reason, identity, model, prompt and completion tokens, and cost.

One run, call by call: the model call, the shell command, the decision, the milliseconds, and the cents. Tap to enlarge.

Use it with your team, with shared controls

Everyone who installs runs under the same rules, risky calls wait for a person to approve them, and every agent's activity lands in one log. You don't hand-write the rules: when an agent hits a block on something legitimate, it proposes the rule with its reasoning, and a person confirms or rejects it in one click.

How a team sets it up, step by step →
ACP approvals page, Approved tab: requests from an agent that hit a step-up rule, each showing the action, who requested it and through which harness, risk tags, the reason, and who allowed it and when.

An agent asked to run something risky. A person allowed it once, and the record shows who and when. Tap to enlarge.

Why developers use it

  • One never list for every agent you run. Claude Code, Codex, Cursor: set it once, not a settings file per tool.
  • A record of every run, in order. Each command, what it touched, and the decision that let it through.
  • What each run cost, call by call, in cents. Not a total at the end of the month.
  • One command to install. Add --local and there is no account at all.

Why teams use it

  • One set of rules for the whole team, whatever agent each person runs. Not whatever each laptop's settings happen to allow.
  • Risky calls wait for a named person. The log shows who approved it and when.
  • One log for every agent on the team, each call tied to the person who ran it.
  • The developer who tried it invites the team. Everyone's agents land in one workspace.
$ curl -sf https://agenticcontrolplane.com/install.sh | bash

Free up to 5 agents. Teams $100 a month for 25. Pricing →

CrewAI, LangGraph, or an SDK? Every way to set up ACP →

Already installed? Open your console →