See, govern, and protect every coding agent and AI app your people use every day.
Every token spent, every action taken, every command run — across your AI coding agents and desktop apps, on one central dashboard you control. On your infrastructure, never ours.
- Runs on your infrastructure
- Source-available
- Air-gap capable
- Fail-open by design
Illustrative — example figures, not live data.
Every user. Every model. Every token.
A per-developer view of who's using which AI, how much it costs, how many sessions they run, and where it runs — the accountability finance and security both need.
| # | User | Team | Primary model | Tokens | Cost | Sessions | Environment |
|---|---|---|---|---|---|---|---|
| 1 | a.sharma | Platform | Claude Code | 8.4M | $1,240 | 42 | macOS · CLI |
| 2 | r.iyer | Backend | OpenAI Codex | 6.1M | $918 | 37 | Linux · CLI |
| 3 | p.nair | Data | Gemini CLI | 4.7M | $690 | 29 | Linux · Docker |
| 4 | v.reddy | Frontend | Claude Code | 3.9M | $560 | 24 | macOS · CLI |
| 5 | s.patel | Platform | Kimi | 2.8M | $410 | 19 | Windows · CLI |
| 6 | n.gupta | Backend | ChatGPT | 2.3M | $360 | 16 | macOS · desktop |
| 7 | k.menon | Security | Claude | 1.9M | $300 | 14 | Linux · desktop |
Illustrative — example figures, not live data. Sensitive values are masked in the real product.
Your company runs more AI than you can see.
Your developers and users run a dozen AI coding agents and apps — each with its own console, its own token bill, its own access to your code. Finance can't attribute the spend, security can't see the commands, and no single dashboard shows who did what.
Spend and activity fragmented across every provider console.
Your existing security stack cannot see terminal coding agents at all — the shadow AI running in your engineering org.
Secrets and PII flow into models with no gate in between.
Illustrative of the category problem — not measured metrics.
One platform. Three planes. Your infrastructure.
AI governance for the coding agents and desktop apps your teams use every day — self-hosted, so you see it, govern it, and protect it without anything leaving your walls.
Visibility
- Token spend and cost tracking — every token, every dollar across Claude, Codex, Gemini, and Kimi — by developer/user, team, project, and cost center.
- Live activity: what each agent is doing right now, its context usage, and full session history.
- Department rollups and chargeback exports your finance team will actually trust.
Control
- Approve or stop an agent's next command from one dashboard — or your phone. Fail-open, so nothing ever hangs.
- Push org-wide guardrails to every machine ("no agent may run
curl | bash") enforced locally. - Govern which MCP servers and tools your people can reach, with a full tool-call audit trail.
Protection
- Purpose-built AI DLP: flag and block PII, secrets, and sensitive data before they enter a prompt or a command.
- Full-content compliance mode for regulated teams: transcripts, command audit, retention.
- Export findings to your SIEM; answer a compliance query in minutes, not a fire drill.
Hub and spokes. Entirely yours.
A lightweight agent (stl) installs on each machine and reads AI session logs read-only. It reports to ST Hub — which you run on your own servers or cloud — where admins get org, department, and per-user dashboards with role-based access. ST Gate, our MCP gateway, governs every tool call. Nothing ever leaves your infrastructure.
Every coding agent. Every app. One graph.
AI coding agents CLI
- Claude Code
- OpenAI Codex
- Gemini CLI
- Kimi
Full token, context, activity, transcript, and approval coverage.
AI desktop apps Desktop
- Claude
- ChatGPT
- Gemini
Usage and — for managed enterprise accounts — prompt/response content via each vendor's compliance API, plus MCP tool-call governance and endpoint presence.
The only governance product that sees your terminal agents and your desktop apps — and stitches both to one employee identity.
Built to do what your security stack can't.
CLI + desktop in one place
Your security stack can't see terminal coding agents. We were built for them first.
One identity graph
CLI sessions, desktop conversations, and MCP tool-calls resolve to one person — the view a department head actually wants.
Sovereign, not SaaS
On-prem or your own cloud. No vendor data processor to review, no data-residency exception, no phone-home.
Fail-open, auditable, source-available
In the path, never in the way — and every line is readable before it runs.
Built for the people accountable for AI.
For the CISO
Command audit, PII/secret prevention, SIEM export, and a governance story that passes works-council and compliance review. No third-party processor.
For the VP of Engineering
See adoption and cost per team, standardize on the right agents with real evidence, and set guardrails without per-team engineering.
For Finance / FinOps
One view of AI spend across every vendor, by cost center, with budgets, alerts, and chargeback exports. It pays for itself.
Bring your AI workforce under control.
See Sentinel Telemetry running on infrastructure you own.