See and control every tool call your agents make.
Your agents act through model and tool calls. ACP records every one, learns the rules from what they hit — proposed by the agent, confirmed by you — and controls what runs — across every agent and framework your team uses. Free up to five agents.
Windows — in PowerShell: irm https://agenticcontrolplane.com/install.ps1 | iex
Prefer fully on-device? Add --local — no account, nothing leaves your machine. what each mode writes →
What did it actually do all day?
Tracing shows you the call. ACP controls the action. Langfuse, Helicone and Braintrust tell you what an agent did after it did it. ACP checks each tool call against your rules before it runs, and records the decision alongside the call.
When a run costs $50 or does something you didn't expect, you need to see what actually happened. ACP records every action in order — each model call and tool call with its latency, tokens, cost, and allow-or-deny decision, plus the real identity behind it. Click any event and see exactly what it did.
It's also where the bill comes from. The same task can run under a cent one time and hundreds of dollars the next, because cost tracks how much context the orchestration loop re-reads to decide its next move — and that scales with how far the run wanders. What is tool call economics? →
- The full timeline — loop, leaf, and tool calls, as they happened
- Per-event cost, latency, model, and the policy decision that gated it
- Loop vs leaf: the orchestration loop re-reading context is usually most of the bill
- Real identity and scopes carried through every delegation hop
- Budget caps that halt the run, deterministically — not just a warning
Your agents draft the changes. You sign them.
Nothing here tunes itself behind your back. ACP reads what your agents actually did and drafts the change — a cheaper route, or a new rule — then waits for you. Nothing takes effect until you confirm it.
The money first. ACP reads your own recorded calls and names the levers — in dollars you actually spent, each with a session that shows it, and a rule you can turn on in one click.
- Side-model calls your harness makes on its own — classifiers, titles, subagents
- The prompt prefix being rebuilt instead of read back from cache
- Long sessions whose last third costs more per turn than their first
Every routing rule starts in shadow: it reports what it would have saved before it changes a single call. How cost tracking works →
The same move, for policy.
When a rule blocks something an agent legitimately needs, it doesn’t work around the block — it proposes a rule: the tool, the tier, the permission, and why, written from the denial it just hit. Proposals queue in the console, and nothing is enforced until you confirm it.
- Each proposal is scoped to one tool and one tier — never a blanket exception
- The agent’s own rationale attached, so you review with context, not guesswork
- Confirm or reject in one click — the human stays the only one who can change policy
Your agent walked in holding 75 tools.
Every request a coding agent makes declares its full tool catalog — the model can't call what it can't see. A real Claude Code session declares 75 tools: the coding loop, yes — and tools that send messages, publish public web pages, schedule their own future runs, and drive your logged-in browser. Most were never invoked. All of them are standing open.
ACP captures the declared surface on the agent's first call — before anything runs — and turns it into a control table: every tool a click to allow, flag, or deny. When the surface drifts mid-session (we've watched one gain 21 tools in an afternoon), you hear about it.
- The full catalog, visible before first invocation
- One click per tool: allow · flag · deny · ask
- Drift detection — know when the surface grows
One curl, one sign-in, your first audit row.
A coding agent in your IDE, a CrewAI pipeline, a LangGraph service, the OpenAI SDK in a script — pick the method that fits your stack. One install, no code changes, and every tool call is controlled. Free up to 5 agents — subagents free, calls unlimited.
One install per stack — the same control plane behind all of them. See every integration →
Open core, hosted control plane. The enforcement modules are six MIT-licensed npm packages you can read and self-host — the hosted control plane is how you run them in production.
You pay for agents that start work. Everything they delegate is free.
Free up to 5 initiating agents — identities that start work, like your coding agent or a scheduled bot. Subagents and delegation chains are free on every plan, and calls are unlimited. Flat monthly bands above: no call meters, no seats, no tax on coverage.
- 5 initiating agents · unlimited calls
- Subagents & delegation chains free
- See, control & price every call
- Hardline floor & approvals
- 30-day audit retention
- 25 initiating agents · unlimited calls
- Shared policies, approvals & roles
- Org-wide audit & cost rollup
- 1-year audit retention
- Named agent list on the bill — verify it yourself
- 250 initiating agents · unlimited calls
- Everything in Team
- Model routing & context guard, shadow-first
- Savings ledger on the bill — found, applied, saved
- 1-year audit retention
- Unlimited initiating agents
- SSO / SAML · SCIM — available on request
- VPC / on-prem / self-host — available on request
- Unlimited audit retention
- SOC 2 evidence exports · DPA / BAA — available on request
All tiers, the initiating-agent explainer, and the FAQ at /pricing →
Control every tool call your agents make.
Free up to 5 agents — no credit card, no call caps. One curl, a browser sign-in, an API key, restart your client — the next tool call is your first row.
Windows — in PowerShell: irm https://agenticcontrolplane.com/install.ps1 | iex
Prefer fully on-device? Add --local — no account, nothing leaves your machine.
Already installed? Open your console →
Rolling agents out across a team? See ACP for teams →
Or email me — I’ll wire it into your agent with you, live.
— David Crowe, founder