Decide what is trusted, and who owns it.
Octic-managed policies apply out of the box, and your custom policies run alongside them. Ownership is derived, not assigned by hand, and every AI agent, MCP server, coding agent, and package ends up approved, unreviewed, or flagged.
- Everything Discover found starts unreviewed. Octic-managed policies, with enhanced protections, and Acme Corp's custom policies then decide each trust state.
- payments-api, a code repository: owner derived through the @payments team to Priya Raman. Approved.
- shadow-summarizer, an AI agent: no owner. Flagged. It connects to mcp-postgres-prod.
- mcp-postgres-prod, an MCP server with production database access: no owner. Flagged.
- Codex, a coding agent signed in with a personal account: no owner. Flagged.
Managed policies from the start, yours alongside them
Policies that Octic writes and maintains, including enhanced protections, apply out of the box. You get a working baseline before you write a single rule.
Add custom policies for what your organization allows and forbids. They run alongside the managed set and decide the trust state of each AI agent, MCP server, and coding agent.
- Octic-managed policies, with enhanced protections, are applied.
- Acme Corp's custom policy mcp-servers-need-owner: every MCP server has an owner.
- mcp-jira is owned by @platform. Approved.
- mcp-postgres-prod has no owner. Flagged.
Ownership is derived, not assigned by hand
A multi-level ownership engine works out who owns each AI agent, MCP server, and API endpoint, level by level. Ownership comes from your estate, not from a spreadsheet someone has to keep current.
Anything the engine can’t place is marked with no owner, so the gaps show up on the map.
- payments-api, a code repository, is owned by the @payments team.
- @payments has member Priya Raman. Owner derived.
- shadow-summarizer, an AI agent, has no owner at the first level. It is flagged.
Approved, unreviewed, or flagged
Every AI agent, MCP server, coding agent, and package starts unreviewed and ends up in one of three states. Policies and reviewers move them between states, and the map shows where each one stands.
Every trust decision records who made it, when, and why. Export the record as evidence for internal and external reviews.
- 10 approved, including support-triage-agent (@support-eng) and mcp-jira (@platform).
- 3 unreviewed, including invoice-extractor (@finance-ops) and mcp-filesystem (@platform).
- 3 flagged, including shadow-summarizer (no owner) and mcp-postgres-prod (no owner).
Is anyone using Claude or Codex on a personal account?
Octic answers from what its sensors see on each host. A coding agent signed in with a personal account shows up flagged, next to the corporate seats, so you can decide what to do about it.
- eng-ws-14, a Linux host with a sensor, runs Claude Code on a corporate account. Approved.
- WIN-ENG-07, a Windows host with a sensor, runs Codex signed in with a personal account. Flagged.
Trust turns findings into decisions
Discover finds each AI agent, MCP server, and coding agent. Trust gives it an owner and a state, Observe shows what it does at runtime, and Remediate turns what is flagged into a finding with an owner. Agentic fixes are coming late 2026.
Put your own estate on the map
Install a sensor on a Linux or Windows host and coding-agent sessions start showing up, with no extra setup. Connect your APIs and the rest of the map fills in.