Skip to content
octic.ai

Octic will propose the fix. Your team will approve it.

Coming late 2026Agentic remediation will propose a specific fix for each risk Trust or Observe surfaces, and nothing will change until a person approves it. Today, every risk is a finding with an owner and an SLA. Here’s a preview.

Preview, coming late 2026: proposal rem_142 on Acme Corp’s map, from Codex on WIN-ENG-07 to Lena Okafor’s approval and the change.
  • WIN-ENG-07, Marcus’s Windows workstation, runs Codex. Resolved: the personal session is revoked and Marcus is on a corporate Codex seat. Approved.
  • Codex has proposal rem_142, which routes to Lena Okafor (@platform-leads).
  • Lena Okafor approves, which unlocks the change: revoke the personal session.

rem_142

Executed

Move Marcus to a corporate Codex seat and revoke the personal session

Risk
Codex session on a personal account
Approver
Lena Okafor · @platform-leads

Audit trail

  1. Proposed by Octic09:14:02
  2. Routed to Lena Okafor09:14:03
  3. Approved by Lena Okafor09:31:40
  4. Executed by Octic09:31:44
Follow the proposal

Execute stays locked until Lena Okafor approves.

A proposal will show the change before it happens

Remediation agents will be AI agents that Octic runs, separate from the AI agents you govern. Each proposal will name the risk that triggered it, the resource, exactly what will change, and who has to approve it.

The map will show the blast radius: what the change touches and what it leaves alone. A fix could quarantine an AI agent, revoke credentials, or update a policy. For a high-severity risk it could propose containment, such as isolating an AI agent or blocking an API endpoint.

Preview, coming late 2026: proposal rem_142 on the map, with its blast radius.
  • Proposal rem_142: Move Marcus to a corporate Codex seat and revoke the personal session.
  • Inside the blast radius: WIN-ENG-07, Marcus’s workstation, and the Codex app it runs, signed in with a personal account.
  • Outside it, unchanged: the OpenAI API, and invoice-extractor, which also calls it and connects to mcp-filesystem.
  • Approver: Lena Okafor.

Every finding goes to whoever owns the resource

This part ships today. Each risk becomes a finding with an SLA, routed to the resource’s owner, derived by Trust. When an AI agent or app has no owner of its own, Trust follows it to the host or team that does. An exception is time-limited, and an admin has to approve it.

When agentic remediation ships, each proposal will route to the same owner. No fix will run without explicit approval, tied to a named person.

How a finding for Codex on WIN-ENG-07 finds its owner.
  • Codex on WIN-ENG-07 has no owner of its own.
  • Octic derives one from the host it runs on: WIN-ENG-07 is owned by @platform.
  • The finding routes to Lena Okafor of @platform-leads, due Oct 5 under its SLA.
  • When agentic remediation ships, late 2026, proposals will route the same way.

Every finding keeps its history

Today, each finding records its own event history, with a timestamp on every event. Export findings as CSV for internal reviews or post-incident analysis.

When agentic remediation ships, what was proposed, who approved it, and what changed will land in the same trail.

Audit trail Coming late 2026 rem_142
  1. 09:13:58OcticDetected · Codex session on a personal account
  2. 09:14:02OcticProposed · Move Marcus to a corporate Codex seat and revoke the personal session
  3. 09:14:03OcticRouted · To Lena Okafor, the derived owner
  4. 09:31:40Lena OkaforApproved · The change as proposed
  5. 09:31:44OcticExecuted · Personal session revoked. Corporate seat assigned.

5events,17m 46sfrom detection to fix

Playbooks will draft fixes for known risks

You’ll write playbooks for recurring risks: a flagged AI agent, a policy violation, a missing owner. When Octic sees the pattern, the playbook will draft the fix.

A drafted fix will still be a proposal. It will wait for approval like any other.

Preview, coming late 2026: three playbooks, each matching a risk on the map and drafting a fix that waits for approval.
  • The “Personal coding account” playbook will match Codex and draft a fix. The fix will wait for approval.
  • The “Flagged MCP server” playbook will match mcp-postgres-prod and draft a fix. The fix will wait for approval.
  • The “AI agent with no owner” playbook will match shadow-summarizer and draft a fix. The fix will wait for approval.

Remediate closes the loop

Discover finds the risk, Trust decides what it is and who owns it, and Observe shows what it does. Today, Remediate turns the risk into a finding with an owner and an SLA. From late 2026, it will propose the fix, a person will approve it, and the change will show up on the map.

Put your own estate on the map

Install a sensor on a Linux or Windows host and coding-agent sessions start showing up, with no extra setup. Connect your APIs and the rest of the map fills in.

Or join the Design Partner Network.