How It Works
Instrument in a day. Enforce in a week.
Arrakis plugs into your AI agent runtime without changes to how you deploy agents. Four steps from zero visibility to full governance.
Connect your agent runtime.
Arrakis connects to your existing agent deployment through two paths: a lightweight SDK for Python and TypeScript, or a transparent HTTP proxy that intercepts agent traffic at the network layer. Both are purely additive instrumentation -- you do not fork your agent code, you do not change how sessions are initialized, and you do not replace your underlying LLM providers.
Works with LangChain, CrewAI, AutoGen, the OpenAI Assistants API, and custom agent frameworks built on raw LLM client calls. If your agent makes tool calls or API requests, Arrakis can see them.
-
Python SDK
Install the
arrakis-sdkpackage and wrap your agent executor. Captures all tool calls, resource accesses, and inter-agent messages automatically. -
HTTP Proxy
Route your agent's outbound HTTP traffic through the Arrakis sidecar proxy. No code changes required. Supports mTLS for production environments.
Define what each agent is allowed to do.
Once an agent is instrumented, you define its permission boundary in the Arrakis dashboard or as a version-controlled config file checked into your repo. The policy model is straightforward: specify which resources the agent can reach, which action types are permitted, and whether default-deny is in effect.
Policies are scoped per agent or per agent type. A fleet of 20 contract-review agents can share one policy. A single privileged automation agent gets its own explicit ruleset. You can also set contextual conditions: time windows, session origin, or user-triggered vs. scheduled.
-
Dashboard Policy Builder
Point-and-click interface for teams that want to set policies without writing YAML. Export as config when ready to version-control.
-
Config File (YAML)
Define policies as YAML and check them into your agent deployment repo. Policy changes go through your normal code review process. Changes deploy on the next agent session start.
Watch every agent session in real time.
The Arrakis console shows every active agent session and every action taken, as it happens. Permitted and blocked events are distinguished by status and color. The live feed updates in near-real time with sub-second latency from agent action to console display.
Policy violations surface with full context: which agent, which rule triggered, which resource was targeted, and what the session state looked like at the time. You can drill into any event to see the full action sequence before it, not just the violation in isolation.
-
Live Event Stream
Filterable table of agent events across your entire fleet. Sort by agent, action type, resource, or status. Violations highlighted inline.
-
Session Inspector
Drill into any session to see a timestamped action trace from start to end. Useful for post-incident review and policy refinement.
Investigate, remediate, and improve policies.
After a violation or incident, the audit trail gives you the complete picture. Every session is preserved with its full action sequence: tool calls, API hits, file accesses, and the policy evaluation outcome for each. You can export structured evidence for compliance review or incident post-mortems.
The policy feedback loop is built in. When a block happens, you see exactly which rule fired and against which action. From there you can tighten the rule, expand it with a justified exception, or flag the agent for redesign. Each policy change is logged with who made it and when.
-
Audit Export
Export full session records in JSON or CSV. Structured for SIEM ingestion or direct use in compliance evidence packages.
-
Policy Iteration Log
Every policy change is recorded: who changed what, when, and the before/after state. Useful for demonstrating governance maturity to auditors.
See the full setup in a live walkthrough.
We connect to a sample agent runtime, define a policy, and show you what the console looks like running against your own agent types.