The Platform
The Arrakis agent security platform.
Real-time behavioral monitoring, policy enforcement, and audit logging for every autonomous AI agent your organization runs.
Capabilities
Built around how agents actually behave.
Four capability areas engineered for the real patterns of autonomous AI agent deployments, not theoretical threat models.
Behavioral Tracing
Every tool call, API request, file access, and inter-agent message is captured in real time. You see not just what the agent did, but the sequence that led there and the context it carried.
Outcome: complete session replay for any agent run, no gaps.
Policy Engine
Define per-agent permission rules that govern which resources an agent can reach, which actions it can take, and under what conditions. Rules evaluated inline, before actions execute.
Outcome: scope creep is structurally impossible, not just monitored.
Integration Hooks
Connects to your existing incident response stack via webhooks, Slack, PagerDuty, and direct API. Agent violation events arrive in the same channels as your infrastructure alerts, with full context attached.
Outcome: no separate security console to learn; violations land where your team already works.
Compliance Export
Export structured audit logs in formats your compliance and legal teams can use. Covers which agent, which session, which resource, and the policy outcome for every action. SIEM-compatible format available on Professional and Enterprise plans.
Outcome: a single source of truth when auditors ask what your agents touched.
Live Console
A live feed of what every agent is doing.
The Arrakis console shows every agent action as it happens: what was called, what responded, and whether the action was within policy.
| Agent | Action | Target Resource | Status | Timestamp |
|---|---|---|---|---|
| contract-reviewer-01 | api_read | legal-docs-api | Permitted | 14:42:09 |
| expense-audit-agent | file_write | finance-reports/q3 | Blocked | 14:41:57 |
| hr-screener-v2 | api_read | HR-datastore | Permitted | 14:41:44 |
| data-pipeline-agent | external_post | partner-reporting-api | Throttled | 14:41:31 |
| infra-diag-agent | api_read | ops-metrics-api | Permitted | 14:41:19 |
| contract-reviewer-01 | external_post | external-llm-api | Blocked | 14:41:03 |
Policy Engine
Policy rules that match how you think about risk.
Define per-agent permission boundaries using a straightforward rule model: resource scope, action type, and contextual conditions like time window or session origin. Rules are evaluated inline before any action executes.
agent: contract-reviewer-01
description: "Legal document review agent"
allowed_actions:
- api_read
- file_read
resource_scope:
include:
- legal-docs-api
- contract-store/*
exclude:
- HR-datastore
- finance-*
denied_actions:
- file_write
- external_post
- api_write
context_conditions:
time_window: 09:00-18:00
default_deny: true
# Any action not explicitly permitted is blocked
# Violations trigger Slack alert + full context log
Audit Trail
An immutable record of every agent action.
Every agent run produces a structured audit trail: who triggered the session, every tool call made, every resource accessed, and the policy outcome for each action. Queryable, exportable, and retained per your plan tier.
Alert Routing
Violations go straight to your incident response stack.
When an agent violates a policy rule, Arrakis fires an alert to the destination you configure. Every alert carries full context: agent name, violated policy ID, affected resource, session ID, and the action that triggered it.
Slack
Post violation alerts to any channel. Message includes agent name, blocked action, policy that triggered, and a direct link to the session audit trail.
PagerDuty
Route high-severity agent violations into your existing on-call rotation. Severity mapping configurable per policy rule.
Webhooks
POST structured JSON event payloads to any endpoint. Integrate with your SIEM, custom alerting pipeline, or ticketing system without vendor lock-in.
Digest and immediate email alerts for teams that are not yet running real-time incident response tooling. Available on all plans.
Ready to see the platform in action?
We walk through a live instrumentation of your agent runtime and show you what governance looks like for your specific deployment.