THE AI AGENT CONTROL PLANE

Let your agents
off the leash.

Every AI tool. Every agent. Refuse the one that hurts.

Your agents load skills, subagents, instruction files, hooks and MCP connectors that nobody approved. Almost all of that plumbing runs locally, on laptops your cloud security never sees. Northbeams runs on the machine, in the path of every tool call, and can refuse one.

Start your 14-day trial Poke the live demo. No signup.
Know every agent. Refuse any tool call. Prove it later.
Two-minute install. First agent manifest within 24 hours. If it names nothing you did not approve, walk away. Free for 14 days either way.
MAC, WINDOWS AND LINUX · BROWSER, DESKTOP, CLI AND MCP

A cloud gateway cannot see the tool running on someone's laptop.

So Northbeams does not sit in the cloud. It runs on every machine you own, in the path of every tool call, and it can refuse one.
WHAT CHANGED THIS YEAR

The agent you approved is not the agent that runs.

An agent is not one app any more. It is a stack: skills, subagent definitions, instruction files like CLAUDE.md, AGENTS.md and .cursorrules, hooks, and MCP connectors. Anyone on your team can add one in seconds. Almost all of it lives in a folder on a laptop, so nothing you run in the cloud ever reads it. In IBM's Institute for Business Value survey of 2,000 CIOs and CTOs in June 2026, two thirds said they are already held accountable for AI systems they do not fully control.

77%
of CIOs and CTOs say AI adoption already outpaces their governance. IBM Institute for Business Value, June 2026, 2,000 CIOs and CTOs.
13.4%
of 3,984 AI agent skills scanned had a critical issue in them. Snyk, February 2026.
24,008
secrets found in MCP config files on public GitHub, 2,117 of them still valid. GitGuardian, 2026.
Sources: IBM Institute for Business Value, June 2026, survey of 2,000 CIOs and CTOs · Snyk, February 2026 · GitGuardian, 2026
SO FAR YOU HAVE THREE OPTIONS
"Agent policy: ask again in Q3"
Ban them.
Turn the agents off and publish the policy. Your best people run them anyway, on hardware you do not manage, and now you see nothing at all.
"Nobody read the skill before installing it"
Trust them.
Assume every skill and connector is fine. Snyk scanned 3,984 AI agent skills in February 2026 and found critical issues in 13.4% of them.
"The agent never touched the proxy"
Buy a cloud gateway.
Route the traffic you already know about, and stay blind to the skill, the hook and the MCP server that never leave the laptop.

There is a fourth option.

THE FOURTH OPTION

Run on the machine. Refuse at the tool call.

Northbeams is the AI agent control plane. A signed desktop agent on Mac, Windows and Linux, plus a browser extension. It sits inside the MCP JSON-RPC path, so a blocked tool call gets a real error back and never reaches the tool. No proxy, no MITM cert, no network change.

Browser
Every chatbot, every tab, every prompt.
Desktop
Every AI app on Mac, Windows and Linux.
CLI
Every coding agent, and the files that steer it.
MCP
Every connector an agent can reach, one tool call at a time.
THE DIFFERENCE

Everyone else covers a slice.
Northbeams covers all four.

BROWSER
DESKTOP
CLI
MCP
Secure web gateway
-
-
-
Endpoint DLP agent
-
-
API / MCP gateway
-
-
-
Northbeams
SEE IT IN ACTION

Thirty seconds inside Northbeams.

Watch it name the agents, score every skill and connector, and hand you the controls. Two products: Sentinel to know and control, Evidence to prove.

SENTINEL · KNOW

Every AI tool and every agent you own, named in 24 hours.

Install it, and by Monday the Manifest screen in Sentinel is full: every agent, skill, subagent, instruction file, connector and hook, on every machine you own. Risk scored. With a person's name against it.

Claude Code skills, subagent definitions, CLAUDE.md, AGENTS.md, .cursorrules, Copilot instructions, hooks and MCP manifests
Scanned at rest on the device. Metadata only, never file contents.
Every agent tied to a real person
GitGuardian found 24,008 secrets in MCP config files on public GitHub in 2026. 2,117 of them still worked.
Unapproved MCP server
internal-db · nobody signed off
Every agent on the chart
with a person's name against it
THE OFFER

Your First Sweep lands within 24 hours.

Every AI tool your people use. Browser, desktop, CLI and network, with the person who used it.
Every agent in your company, by name. Sorted approved, unknown and high-risk.
Every skill, instruction file, hook and connector. Risk scored, with the person who added it.
Every MCP server your agents can reach. Tool by tool, so you can refuse one without switching the agent off.
It is the document most buyers forward to their CEO the same week.
Start your 14-day trial
If it doesn't name agent plumbing nobody approved, walk away. It's free for 14 days either way.
14-DAY TRIAL · CARD REQUIRED · TWO-MINUTE INSTALL
SENTINEL · CONTROL

Block, warn, redact or allow. At the tool call.

Northbeams sits inside the MCP JSON-RPC path. A blocked tool call gets a real error back, so it never reaches the tool. The agent keeps working. One tool call does not.

Stop it before it leaves.
Prompts are classified on the device, so the raw content never leaves the machine. Only the decision is logged.
Draft an email to Acme Corp about the renewal at $84k and cc jane@…
✕ BLOCKED
⛨ 3 redacted on-device
Approve in Slack.SIGNAL FLAGS
Turn a block into a 30-second yes, in the channel your team already lives in.
NorthbeamsAPPDirect message · 9:12 AM
Priya (Operations) wants to connect an unapproved MCP server to her AI assistant. Approve for this session?
Approve Deny Redirect
✓ Approved · Priya can proceed
Undo
Send them to the right one.COACH
A blocked AI tool shows your own branded page, naming the one you approved.
unapproved-ai-tool.com
blocked
Use the approved tool
your logo, your wording
Kill it in one click.CLOSE THE HARBOR
Block every agent on every laptop the moment something goes wrong.
Harbor open
Flip to block everything, everywhere
ARMED
EVIDENCE · PROVE

Proof an auditor can check without trusting us.

Every evidence pack is hash-chained and signed with RSA-2048 (RS256). The public key is published at /.well-known/jwks.json, and there is a public verification endpoint. A third party can verify a pack offline. Nobody has to take our word for any of it.

HASH-CHAINED SIGNED RSA-2048 (RS256) PUBLIC KEY PUBLISHED VERIFY OFFLINE
Know. Control. Prove. Two products, Sentinel and Evidence, and nothing else to buy.
LIVE IN AN AFTERNOON
01
Install.
Signed desktop agent on Mac, Windows and Linux, plus the browser extension. Two minutes. No network change.
02
Know.
Your First Sweep lands within 24 hours. Every AI tool, and every agent.
03
Control.
Turn on blocking, approvals and the kill switch when you are ready.
WHAT WE SEE

10,000+ AI tools. 10,001 MCP servers. Four surfaces. One dashboard.

We track every major AI tool and every MCP server we can find, and we add new ones every day. We publish our coverage, including what we miss. Most vendors show you a logo wall. We show you the scorecard.

ChatGPT Claude Gemini Copilot Cursor Perplexity Midjourney Notion AI Windsurf Ollama Replit v0 Grammarly Otter Poe LM Studio ChatGPT Claude Gemini Copilot Cursor Perplexity Midjourney Notion AI Windsurf Ollama Replit v0 Grammarly Otter Poe LM Studio
See the coverage scorecard
THE MAP REDRAWS ITSELF: NEW AI TOOLS AND MCP SERVERS SPOTTED THE DAY THEY APPEAR · REFRESHED EVERY MORNING
WORKS WITH YOUR STACK

Deploys with your MDM. Streams into your SOC.

Splunk Microsoft Sentinel Intune Jamf Kandji Okta Entra ConnectWise
GTIA PREMIUM MEMBER · DRATA ALLIANCE MEMBER · INDEPENDENTLY PENETRATION-TESTED
WORD FROM THE HARBOR

Trusted by the people who get paid to be skeptical.

Digital Works Group

Clients are already accountable for the AI their teams use. Northbeams is the first tool we have seen that turns that into evidence an auditor will actually accept.

Rafael Bloom
Rafael Bloom
Partner, Digital Works Group
Garde1

We ran a First Sweep for a client who swore they had five AI tools. It found 41. That one report sold our AI governance service in a single meeting.

Michael Hayles
Michael Hayles
Garde1
Comtrig

We pushed it out through our RMM in an afternoon and every client landed in one console. It is the first security line item our clients renew without being chased.

Idan Barzilay
Idan Barzilay
Comtrig

“The First Sweep found 34 tools we had never heard of. I put it in front of the board that week, and nobody has questioned the budget line since.”

CISO, 400-person fintech

“We caught two coding agents running with production credentials in the first week. That alone paid for the year.”

Head of Platform Engineering, B2B SaaS

“I stopped being the department of no. Approvals come back in minutes now, so people actually ask first.”

IT Director, professional services firm

“Our EU AI Act evidence used to be a spreadsheet and good intentions. Now it is an export.”

GRC Lead, healthcare technology company
MEMBERSHIPS & INDEPENDENT REVIEW
DrataALLIANCE MEMBER GTIAPREMIUM MEMBER INDEPENDENTLY PENETRATION-TESTED
WHY BUYERS PICK NORTHBEAMS

Everyone else promises you'll be safe. We promise you'll be fast.

Safe is table stakes. The companies that win this era will be the ones that ran the most agents without wrecking. Ban the agents and your best people run them where you cannot see. Trust them and you are betting the company on plumbing nobody read. The third move is command: know every agent, refuse any tool call, prove it later.

That is what an agent control plane is for.
WHY WE BUILT NORTHBEAMS

Every company we work with had the same blind spot. Agents were doing real work across browsers, desktops, terminals and MCP clients, and the skills, instruction files and connectors steering them sat in folders nobody had ever read. Northbeams closes that gap. We run one of the most agentic operations in the category, and we govern our own agents with Northbeams before it ships to you. Know every agent by Monday, and control it the same day.

The Northbeams team
The control plane for AI agents at work
PRICING

Twelve dollars a person. The whole product.

SENTINEL · MOST TEAMS START HERE
$15/ seat / month, or $12 billed annually
All four surfaces, the fleet-wide agent Manifest, per-user attribution, one-click enforcement, the MCP Gateway and the signed evidence pack. Nothing held back for an upsell.
14-day trial, credit card required. Every price on the pricing page is the real price.
ENTERPRISE · FOR FLEETS
Custom
The same product, sized for a fleet: SSO and SCIM, SIEM streaming, data residency, volume pricing, and a named team that gets you deployed.
Quoted to your deployment.
See pricing
FOR MSPs AND MSSPs

Your clients are turning agents loose. Be the one with the answer.

Run agent governance as a monthly service line: one console for every client, reports under your brand, deployment through the RMM you already use. One console. Every client. Your margin.

Become a Harbor Master
SIGNED EVIDENCE If an auditor asked today, what would you show them? An export they can verify themselves, offline. See the trust center →

The agents are already running. The only question is what they can reach.

You stop being the department of no. You become the person who let the agents off the leash and kept the receipts. One install. One dashboard. By Monday.

Start your 14-day trial Poke the live demo. No signup.