Agentic Control Plane

Your agents never sleep. Control them so you can.

Every tool call and model call your agents make passes through ACP — logged, priced, and with your policies set deterministically. See what they did, stop what you’d never allow, and know why it cost what it did. Works wherever you run agents across every common agent framework and harness.

$git push --force origin main
humanAPPROVED
floorDENIED
ruleprotected-branch · logged ~/.acp/audit.jsonl
Some actions stay one rule away from impossible — not even an approved click reaches them. This one happens on camera below.
$rm cleanup.sh
policyHELD FOR APPROVAL
ruledestructive-delete → ask · Jul 20
Our own agent, mid-session — while it was setting up approvals for another agent. The agent building the cage got caged.
>daily model budget · exceeded mid-run
budgetCAP HELD
rulellm-daily-cap · halted, not warned · Jul 21
The agent had admin access to raise its own cap — and declined. The net held against its own author.
$gcloud run services update-traffic api --to-revisions hotfix=100
policyDENIED
ruledeploy-via-pipeline · mid-incident · Jul 21
The deny didn’t block the fix — it blocked the shortcut. The fix shipped through review: ten minutes slower, auditable forever.
$gh pr merge 41
brokerBROKERED
rulecredential-broker · short-lived minted token · Jul 21
Denied first — GitHub wasn’t connected — then run on a token ACP minted for the job. The local credential never left disk.
>model spend · $15/day · unmetered key
meteringCAUGHT
ruletraced to the one container outside the plane · Jul 21
The bill that surprises you is always from the agent you didn’t control.
Watch the first one happen — 60 seconds →  ·  all real, all ours — the full log
# free for individuals · one command · every agent
$ curl -sf https://agenticcontrolplane.com/install.sh | bash

Prefer fully on-device? Add --local — no account, nothing leaves your machine. what each mode writes →

tool and model calls controlled to date · metered, not estimated
/ what acp does

ACP does three things well.

1 · Deterministically control your agents

Autonomous or interactive: allow, ask, or deny on every single action, by rule. The same call gets the same decision every time — no model in the loop deciding your safety.

2 · Turn real behavior into the right permissions

Watch what your agent actually does, then make it policy. Shadow mode replays your last week of real calls and shows what would have been denied — before anything blocks.

3 · Know why it behaved — and cost — what it did

Every run traced action-by-action: each call’s cost, latency, and the decision that gated it. When a run costs $50, you can see exactly why.

Claude Code, Codex, Cursor, opencode, OpenClaw, CrewAI, LangGraph — each ships its own permission system, with its own rules in its own place. ACP is one set of rules, enforced across all of them. See every integration →

/ is this you?

You shipped an agent. Now it's a black box.

You wrote checks to keep the agent from doing something dumb. They hold while you babysit it — and the whole point of handing off is that you stop watching. If any of these is you:

The bill is a mystery

Same task, wildly different cost — and you find out from the invoice, not the run.

It touches risky data

It reads your .env, pulls customer PII, pipes secrets straight into a prompt — and you can't see what left the building.

Many agents, no single control panel

Every team ships in a different framework — and there's no one place to see or control them all.

/ cost

The same task cost 0.9¢ — and $501.

Averages lie. That’s one real coding agent on the same kind of task, across 72 runs — 0.9¢ at the median, $501 in the tail. Cost tracks how much context the orchestration loop re-reads to decide its next move, and that scales with how far the run wanders. One number can't tell you whether an agent is cheap or a runaway waiting to happen.

  • Every run as one dot — median, middle-80% band, and the expensive tail
  • Failed runs called out — you pay for the ones that never finish, too
  • Loop vs leaf: the orchestration loop re-reading context is usually most of the bill
  • Budget caps that halt the run, deterministically — not just a warning
What is tool call economics? →
ACP cost-per-run distribution for one agent across 72 runs on a log scale: median 0.9¢, spanning under 0.1¢ to $501.61, with the middle-80% band shaded and 20 failed runs marked in red — the same agent's cost varies by orders of magnitude from one run to the next.
/ trace

What did it actually do all day?

When a run costs $50 or does something you didn't expect, you need to see what actually happened. ACP records every action in order — each model call and tool call with its latency, tokens, cost, and allow-or-deny decision, plus the real identity behind it. Click any event and see exactly what it did.

  • The full timeline — loop, leaf, and tool calls, as they happened
  • Per-event cost, latency, model, and the policy decision that gated it
  • Real identity and scopes carried through every delegation hop
Debug one agent run, action by action →
ACP session trace: a per-event timeline of one agent run — llm.proxy.anthropic loop and leaf calls interleaved with Bash and Read tool calls, each stamped with latency, tokens, cost, and an allowed badge. The selected model call's detail panel shows decision reason, latency 3603ms, client claude-cli, identity apikey, scopes, model claude-fable-5, 762 prompt tokens, 24 completion tokens, and 0.9¢ cost.
/ tool surface

Your agent walked in holding 76 tools.

Every request a coding agent makes declares its full tool catalog — the model can't call what it can't see. A real Claude Code session declares 76 tools: the coding loop, yes — and tools that send messages, publish public web pages, schedule their own future runs, and drive your logged-in browser. Most were never invoked. All of them are standing open.

ACP captures the declared surface on the agent's first call — before anything runs — and turns it into a control table: every tool a click to allow, flag, or deny. When the surface drifts mid-session (we've watched one gain 21 tools in an afternoon), you hear about it.

  • The full catalog, visible before first invocation
  • One click per tool: allow · flag · deny · ask
  • Drift detection — know when the surface grows
The Tool Surface Index — Claude Code, Codex, live captures →
ACP tool-surface control table for a live claude-code agent: 76 tools declared, 23 denied, 25 flagged, 44 never invoked, with a surface-drift banner (gained +76 tools). A one-click suggested posture offers to deny 2 never-invoked outward-blast-radius tools (CronList, Workflow), and every tool is a row with allow / flag / approval / deny — CronCreate and the Gmail connector shown denied, SendMessage and WebSearch flagged.
/ personas

Pick the agent you run. The rules come written.

Five ready policies at the level you already think — “an unattended agent that can’t touch the shell.” Assign one in shadow: it replays your last week of real calls and shows what it would have denied, and nothing blocks until you click enforce.

What each persona allows, pauses, and denies — attended and unattended →

/ get started

Your first audit row in thirty seconds.

A coding agent in your IDE, a CrewAI pipeline, a LangGraph service, the OpenAI SDK in a script — pick the method that fits your stack. One install, no code changes, and every tool call is controlled. Free for individuals, forever. $15/seat for teams.

No account required Runs on your machine No code changes Works with your existing AI clients and frameworks Uninstall anytime
How to install
# Hook · Claude Code · Cursor · Codex — free for individuals
$curl -sf https://agenticcontrolplane.com/install.sh | bash
    detected runtime · registered hooks · workspace connected
# now just run your agent — every tool call is checked before it runs:
$ claude "refactor the auth module"
    fs.write app/auth.ts   ALLOW · logged · priced
    shell.exec rm -rf /  DENY · policy
# fully on-device instead? add --local — no account, nothing leaves your machine

One install per stack — the same control plane behind all of them. See every integration →

Open core, hosted control plane. The enforcement modules are six MIT-licensed npm packages you can read and self-host — the hosted control plane is how you run them in production.

/ pricing

Free for individuals, forever. Per-seat for teams.

Every feature works free for one person — unlimited calls, agents, and clients. Seats start when you add a second person: one price per human, covering every AI tool and agent they run.

Individual
One person, every client, every agent
$0forever
  • Unlimited calls, agents & clients
  • See, control & price every call
  • Full audit, cost & policy
  • Hardline floor & approvals
  • 30-day audit retention
Start free →
Enterprise
Compliance, scale & deployment control
Let’s talk
  • Volume seat pricing
  • SSO / SAML · SCIM
  • VPC / on-prem / self-host
  • Unlimited audit retention
  • SOC 2 evidence exports · DPA / BAA
See ACP for teams →

See full pricing details, FAQ, and examples at /pricing →

Tracing shows you the call. ACP controls the action.

Control every tool call your agents make.

Free for individuals, forever — no credit card, no call caps. See your first controlled tool call in about thirty seconds.

# free for individuals · no credit card
$ curl -sf https://agenticcontrolplane.com/install.sh | bash

Prefer fully on-device? Add --local — no account, nothing leaves your machine.

Already installed? Open your console →

Rolling agents out across a team? See ACP for teams →

Or book 30 minutes — I’ll wire it into your agent with you, live.
David Crowe, founder

ACP audit console: a live feed of tool calls with allow / redact / block decisions, tokens used, and metered cost.