Nexus / AI Agent Governance & Observability

Know what your agents do.
Keep control of what happens next.

See everything your AI agents do, block what they shouldn't, and cut what they cost. Nexus captures every agent action, enforces policy in-flight, and traces every agent, identity, and connection.

Early Beta

ONE FAMILY / THREE CONNECTED SURFACES01 Developer activity
02 Capture & policy
03 Shared evidence

From the local session to the enterprise decision.

Close to the work.
Clear across the estate.

Console, DevTools and the desktop workspace are parts of one family. The role differs; the evidence connects.

Nexus console

See the estate. Find the exposure. Direct the response.

An enterprise view of agents, identities, connected systems and developer activity. Investigate findings, inspect policy decisions and understand the evidence behind reported costs.

  • Agent and identity inventory with relationship and exposure views.
  • Findings, policies and pending approval records in a shared governance surface.
  • Token attribution and application cost views that distinguish reported usage, derived prices and missing evidence.
  • Shared Swfte sign-in and an authenticated backend proxy are implemented in current source.
Integration availability and boundaries
  • Data availability depends on connected producers; missing cost and governance history remain absent.
  • The current canonical console is /v2. Older /nexus, /v2c and /v2-legacy routes redirect; some retired surfaces have no modern equivalent.
  • Local source inspection does not establish current cloud availability, tenant configuration, certification or a service-level commitment.

Every agent action,
captured at the source.

Nexus wraps the agent runtime itself. Events stream from the terminal to a durable local ledger, then roll up to the governance console: who did what, in which repo, on which terminal.

EventWhenWhat Nexus records
sessionAgent session startsTerminal ID, user (git email), repo, branch, commit, model and provider
promptEvery prompt submittedFingerprint and length only at the default privacy tier. No prompt text leaves the machine
tool_actionBefore every tool callTool, target, and a blocked flag with the policy reason when Nexus says no
dependency_installnpm / pnpm / yarn / pip / mvn / cargoPackage and version, giving supply-chain visibility for every agent-initiated install
file_changeEvery edit or writeRepo-relative path plus a protected flag when a policy-guarded file is touched
token_usageEvery turnInput, output, baseline vs. compressed tokens, savings, and cost

Privacy by default: at the standard capture tier, prompt content is never stored — only a fingerprint and length.

Governance
that pays for itself.

The same event stream that powers the audit trail meters every token. Nexus attributes AI spend per terminal, per repo, and per user, and measures exactly what context compression and output filtering save you.

01 / Savings

Baseline vs. actual

Every turn records baseline tokens, compressed tokens, and the delta, so savings are measured, not estimated. You see the real cost of every session and what it would have cost without optimization.

02 / Savings

Cost attribution

Spend rolls up by user, repo, terminal, and model. Runaway sessions and expensive workflows surface immediately instead of at invoice time.

03 / Savings

Waste elimination

Per-command output filtering and context compression cut the tokens agents burn on verbose tool output: typically the largest single source of avoidable agent spend.

Trace every agent.
Every connection. Every change.

Observability tells you what happened. Nexus also decides what is allowed to happen, and maps the identities and connections behind it all.

01 / Governance

In-flight policy blocking

Nexus sits between the agent and your system. Protected files, forbidden commands, and unapproved dependency installs are denied before they execute, with the reason logged to the audit ledger.

02 / Governance

Audit trail: prompt → change → why

Every change an agent makes is traceable back through the tool action and the prompt that caused it. Security review stops being archaeology; the trail is already assembled.

03 / Governance

Shadow-AI detection

Unmanaged agents, unsanctioned model providers, and unknown non-human identities surface as findings. This is the AI usage your existing SaaS security tooling cannot see.

04 / Governance

Identity graph + blast radius

Every agent and non-human identity in one inventory, with a connection graph that answers the question that matters in an incident: if this credential is compromised, what can it reach?

05 / Governance

Supply-chain visibility

Agent-initiated package installs are first-class events. Know which agent added which dependency, in which repo, on which terminal, before it ships.

06 / Governance

Policy-as-code

Governance rules are declared, versioned, and evaluated continuously, rather than captured as screenshots of settings pages. Findings show exactly which policy failed and where.

Start where the work is.
Broaden when the evidence is.

01 / Rollout

Start with visibility.

Connect supported developer workflows and establish what is captured, what is missing and what is attributable.

02 / Rollout

Agree the controls.

Choose the policy boundaries and approval responsibilities that are appropriate for the environment.

03 / Rollout

Expand the evidence.

Review coverage and adoption before broadening the rollout. Keep the gaps visible.

Go deeper.
No email wall.

Ungated guides on the problems Nexus was built for: no email wall, no PDF download.

Before you
make a start.

What is Swfte Nexus?

Nexus is an AI-agent governance and observability platform. It captures what coding agents like Claude Code actually do: every session, tool action, file change, dependency install, and token spent. It enforces policy in-flight by blocking violations before they execute, and gives security teams an inventory of agents and non-human identities with an identity graph and blast-radius analysis.

How does Nexus capture agent activity?

A lightweight wrapper hooks the agent runtime (for Claude Code, via native hooks) and streams structured events to a local collector and durable ledger. Events flow to the Nexus console for per-terminal, per-repo, per-user visibility. At the default privacy tier, prompts are captured as fingerprint and length only. No prompt text is stored.

Can Nexus block an agent action, not just log it?

Yes. Nexus evaluates policy before the tool call executes. Protected files, denied commands, and unapproved installs are blocked in-flight, with the reason recorded in the audit trail. That is enforcement, not just observability.

How does Nexus reduce AI spend?

Nexus meters token usage per turn (input, output, baseline versus compressed) and attributes cost per terminal, repo, and user. Teams use it to find runaway sessions, enforce budgets, and measure what context compression and output filtering actually save.

Does Nexus work with agents other than Claude Code?

The capture wrapper is agent-agnostic by design; Claude Code is the deepest integration today via its hook system. The governance console inventories any agent or non-human identity reachable through its connectors, and transcript import covers agents without native hooks.

Is Nexus open source?

Nexus is open-core. Capture, forwarding, and enforcement are open source and always available. The intelligence layer, covering audit trails, metrics, knowledge harvesting, and security modeling, runs against an Enterprise backend: either Nexus cloud or self-hosted.

Implementation evidence is based on current Nexus repositories. It does not establish commercial availability, universal agent coverage or any deployment-specific security guarantee.

Plan a rollout
you can evidence.

See what your agents are actually doing

Nexus gives you governance, observability and spend control across every agent you run.