The control plane for every AI agent you run.
See every AI agent. Govern every action. Prove every decision. On Macs, servers and cloud today. Windows and the browser are on the roadmap.
AI agents can reach more than anyone approved.
On paper, AI agents follow your policies. In practice, they can reach source code, credentials, customer data, and systems of record, and most of that reach has no owner watching it.
Agents stay inside the rules.
Most companies assume their approval process limits what agents do.
Agents can reach far more.
An agent inherits the access of whatever runs it, and can read, send, or act far beyond what anyone signed off on.
Blocked and logged.
GIRD blocks actions outside each agent's policy and logs every attempt.
One control plane for every AI agent.
GIRD connects to where your agents already run. Security gets one place to see agents, govern them, and prove what they did.
Every agent, every surface.
A live inventory of every AI agent across the company, known and shadow, each tied to a real person and team.
One policy per agent.
Decide what each agent can use, which other agents it may hand tasks to, and which skills it may load.
A record you can defend.
Every action lands in a tamper-proof audit trail, built for incident response, compliance, and liability.
| Agent | Surface | Owner · Team | Policy |
|---|---|---|---|
| code-assistant-07 | Mac · laptop | P. Nair · Platform Eng | Governed |
| support-copilot | Cloud · us-east | Support · Tier-1 | Governed |
| data-analyst-bot | Servers · finance | A. Rao · Analytics | Review |
| unknown-agent · mac | Mac · laptop | No owner, quarantined | Blocked |
Illustrative example.
Six of the capabilities that make up the platform.
Here are six of the nine. See them all on the Products page.
Agent Registry
See every AI agent in your company, known and shadow, each with a real owner and team.
Tamper-Proof Audit
A record of every agent action you can prove, built for liability and compliance.
Identity Sync
Connect Okta, Microsoft Entra ID, or Google Workspace, and each agent picks up your teams and policies.
MCP Registry
Approve which MCP servers, the tool connectors agents call, your agents may use. Block the rest by default.
PII Protection
Catch sensitive data before an agent can send it anywhere it shouldn't.
Telemetry & Observability
Watch what every agent does, as it happens.
Wherever your agents run.
Macs, servers and cloud today, all reporting to one control plane. Windows and the browser are on the roadmap. See each surface in depth.
Mac
Windows
Servers
Any cloud
Browser
Available now: Argus for Mac
Free for individuals. Roll it out to your fleet through your MDM.
Every agent gets a real owner, and your existing policies.
Connect the identity provider you already use. Every AI agent is automatically tied to a person and a team, and inherits the access policies you already trust.
When an agent acts, your audit trail shows the agent did it, and who owns it. Not just “the user deleted the file.”
Where we stand today.
Your data
What Argus sends to GIRD, and how long we keep it, is listed in our privacy notice.
Coordinated disclosure
Found a security flaw in GIRD's own software or this site? See our responsible disclosure policy. We acknowledge within 2 business days, fix high-severity issues within 30, and credit good-faith researchers.
Security reviews
We complete your CAIQ, SIG, or own security questionnaire during onboarding. We don't hold SOC 2 yet; see the FAQ below.
What is GIRD?
GIRD is the control plane for the AI agents running across your company, on Macs, servers and cloud today, with Windows and the browser on the roadmap. It gives security one place to see every agent, one policy to govern what each one can do, and a tamper-proof record that proves what they did.
What is Argus?
Argus is GIRD for the Mac. It lists every AI coding assistant on your team's Macs and who owns it. It keeps credentials and sensitive files out of reach, catches sensitive data before it leaves, and keeps a tamper-proof record. Companies deploy it to their Macs through their MDM, so developers install nothing.
Which platforms does GIRD support?
Macs today, through Argus, plus servers and any cloud (AWS, Azure, or Google Cloud). Windows and the browser are on the roadmap. Every surface reports to one control plane under one per-agent policy.
How is Argus deployed?
Argus deploys through the MDM you already run: Jamf, Microsoft Intune, Kandji, or Workspace ONE, with nothing for developers to install or change. It reports into the GIRD control plane alongside your servers and cloud.
Is Argus free?
Yes. Argus is free to download and use on a Mac. Team and Enterprise rollouts add a fleet-wide console, identity sync, and compliance support, and are agreed in a signed contract. Book a demo to talk to us.
What data does GIRD see, and how long is it kept?
What Argus sends to GIRD, and how long we keep it, is listed in our privacy notice.
How do you prove what an agent did?
Every agent action is written to a record that's tamper-proof by design: entries can't be quietly altered or removed after the fact. Each action is tied to a real owner, so when an auditor or incident responder asks "who did this, and was it allowed?", you have the record.
Are you SOC 2 certified?
Not yet. We haven't begun a SOC 2 audit; when we complete one, we'll publish the report on this site. In the meantime we're glad to share our current security posture and controls under NDA, and to complete your own security questionnaire during onboarding.
See GIRD on your own agents.
Tell us which AI agents you run, and we'll tailor the demo.