Agents
Who's running, and what they're doing
Checking Warp…
—
live agents
—
AI egress
—
open deviations
—
provider mismatches
—
over budget
AGENT-TO-AGENT ACTIVITY
who's talking to whom · click an agent
━ talking ╌ undeclared peer ╌ cross-host
Loading activity…
Tags are set on each agent when it starts, and are how you write group policy. Filter the fleet by tag above.
By type · open
| Agent | What happened | Declared → seen | Severity | Last seen |
|---|
Every row acts on new traffic, not the flow that triggered it — Maya reports and contains, it doesn't retroactively unsend. Budget figures are volume estimates, not exact token counts.
| Group | Matchers | Expands to now | Ver | |
|---|---|---|---|---|
| Loading destinations… | ||||
Destination groups are reusable allow/deny targets. Provider catalogs (ALL-LLMs, per-provider) are predefined and read-only; add your own from Network · Name · Catalog · Semantic · Special matchers. Expands to now resolves each matcher via SNI + CIDR — provider naming is CIDR-confidence (coarse), never rendered exact.
| Applies to (tags) | Action | Members | Priority | |
|---|---|---|---|---|
| Loading group policies… | ||||
Group policy attaches an action to every agent carrying a set of tags — new matching agents inherit it automatically. Enforcing actions ask you to confirm the count first. Actions: watch · alert · block. Removing a policy clears it everywhere.
Auto-block on high-severity deviations
Loading…
| Agent | Action | Scope | |
|---|---|---|---|
| Loading rules… | |||
▸ Advanced — low-level policy API (power users)
Beyond the tag-group and single-agent controls above, policy can be written directly against the management API — agent-scoped or CIDR-prefix rules via POST /api/v1/policy (see the API docs / your SIEM integration). Day-to-day policy is written by tag group above; most operators never need the raw API. (No in-console rule builder — this describes the API, not a form here.)
Collector
Export enabled
Status
—
Export is OTLP telemetry emission (metadata-only by default, payload-blind). It is the outbound half of bring-your-own-judgment — not traffic mirroring.
Escalation audit log
—
Export feeds your SIEM or judgment engine — findings and telemetry over OTLP, metadata-only by default. This is the SIEM/BYOJ-outbound path.
Components
Connected hosts
—
Setpoint
Baseline monitor — …
pauses LLM assessments only · baseline preserved · cap 20/min always on
Live logs
live
Warp · Weaver · Loom · Setpoint
connecting…
▸ Advanced — diagnostics & build info
Component build hashes, ABI versions, per-host protocol compatibility, and BPF diagnostics live here for support/debugging. Not needed for normal operation.