A coding agent edits files, runs shell commands, opens network connections, and spends money. Guardrails on the prompt govern none of that. ClawMetry watches the actions themselves, and gives your security team the inventory, the detection, and the stop button.
Your developers already run coding agents, on laptops and in CI, across 30 runtimes and counting. Nobody asked security first, and telling them to stop is not a plan. What you need is the ability to answer three questions at any moment:
ClawMetry exists to make all three answerable, without changing how your engineers work. Observation is read-only. Enforcement is a separate, opt-in step that you control.
Detectors run over the action stream, not the prose. They ask two questions: is this agent stuck, and is it doing something it does not normally do.
Thresholds are calibrated per runtime and learned from your own cohort's baseline, and every incident records which source produced its threshold, so you can tell a measured number from a shipped constant. Incidents are ranked by the estimated spend at risk in dollars. Where no cost is known we say so and rank it accordingly, because sorting a queue by an invented dollar figure is worse than not sorting it at all.
Everything in this section ships off by default. A governance tool that silently changes agent behaviour is a risk of its own, so turning enforcement on is a deliberate act with locks on it.
An autonomous policy acts only when three separate conditions hold: the policy itself is set to act rather than monitor, enforcement is enabled on that node, and the licence check passes. One setting on the node disables every policy at once. Until all three are open, the engine runs in dry run and produces a decision log you can audit before you trust it.
Enforcement depth also varies by runtime. Some agents expose a hook we can gate on; others only emit telemetry after the fact, so there we can observe and alert but not block. Where a control cannot work we label it advisory instead of letting a button quietly do nothing. Ask for the conformance matrix and we will tell you which of your runtimes fall into which category before you buy.
On certifications themselves we publish the honest position rather than a logo wall: see the security page for what we have and what we do not.
ClawMetry is not an EDR, not a DSPM, and not an identity provider. It does one job: visibility and control over what AI agents do and spend, across every runtime your engineers picked. It feeds the tools you already have through the SIEM export instead of asking to replace them.
And it is open source. The collector that reads your engineers' sessions, the detectors, and the enforcement path are public code you can audit before you deploy them. We think the oversight layer should be held to a higher standard than the agents it watches, and that standard starts with being inspectable.