Discovered from GitHub
Repo scanning proposes candidates with AI-drafted descriptions and owners inferred from commit history — no catalog-info.yaml to commit to every repo. Nothing enters the catalog silently.
Connect GitHub. Services, owners, tiers and 32 scorecard rules are already modelled — first scorecards in minutes, and agents that can act on the catalog safely.
Self-serve signup. Free plan: no card, no LLM key.
Works with your stack
Onboarding
What you actually run becomes the catalog: proposed for you, confirmed by you. Connect GitHub and Kubernetes — first scorecards in minutes, not weeks.
Repo scanning proposes candidates with AI-drafted descriptions and owners inferred from commit history — no catalog-info.yaml to commit to every repo. Nothing enters the catalog silently.
One Helm chart discovers every workload: outbound-only, read-only, no per-service setup.
Running workloads missing from the catalog get flagged, and so do catalog entries with nothing behind them.
Services, databases, containers, ingresses and more are already modelled.
Also included
Compliance
Security, Ownership and Delivery start scoring the moment you connect GitHub. No rules to write first.
Your payment service is held to a higher bar than an internal tool.
Every scorecard points at the single rule standing between you and the next tier.
They post as GitHub checks, so a drop is caught before it merges.
How it works
AI Readiness
Before you point an agent at a service, know whether it's ready for one.
Rules that check whether a service is ready for an agent to work on, so you know where you can safely point one.
Agents
Purpose-built agents — or build your own from scratch.
Answers questions about the catalog — ownership, compliance posture, repos — so nobody's hunting through Slack for who owns what.
Finds and runs the right self-service action for a day-2 task — scaling, restarts, provisioning.
Summarises a newly opened incident with the service and owner already resolved, the moment it opens.
Investigates a newly failing rule and proposes the exact pull request that fixes it.
Governance
Decisions route to a human when they should, and every step stays on the record.
Per-tool access levels
Set on every tool of every connected MCP server.
Agents run with only the tools you grant. Nothing else exists to them.
Any action can require human approval, and the approver can never be the person who requested it.
Block a tool while a request is waiting and that request can no longer be approved. Policy applies at decision time, not submission time.
Every agent action, approval and tool change is recorded, enforced at the database. Nothing gets removed, only appended to.
MCP security
A tool's description is executable code.
Real incidents have already exploited exactly this — credentials silently exfiltrated, malicious changes auto-executed on the next interaction, after the tool had already been reviewed and approved. A change after sign-off doesn't require a new approval. Unless you pin it. (CVE-2025-54135, CVE-2025-54136)
The definition a human approved is the only one your agents are ever shown.
Checked automatically about every 10 minutes, or on demand. We diff the whole input schema — types, required fields, enums, bounds — not just the description.
Unattended automation is refused outright; chat needs per-call approval — until someone reviews the diff and re-pins.
What actually needs a human rises to the top, identical changes group together, and every diff sits side by side.
One click holds a tool back from every agent on the connection, without waiting for the next drift check.
Pricing
You pay for builders. Everyone who reviews, approves or audits is free on every plan — guardrails shouldn't cost extra.
$0
Evaluate with your whole team. No card, no LLM key.
$29/builder/mo · 5 builder minimum
For teams running agents in earnest.
Let's talk
Limits, audit retention and onboarding shaped around you.
Services, owners, dependencies and scorecards, proposed from what you actually run and confirmed by you. Then point an agent at the services that are ready for one.