Monitor
Prompts, tool calls, file intents, observed effects, commands, artifacts, and network targets.
Crate protects the execution layer: tools, files, shell commands, memory, skills, network calls, and the artifacts agents leave behind.
Prompt filters inspect language. Crate governs what the agent actually does.
App-layer governance sees what tools report. Crate records intent, effects, artifacts, and policy evidence.
Gensee Crate is an execution-aware security layer for AI agents. It turns agent intent, runtime evidence, and artifact provenance into policy decisions before risky actions complete.
Once agents can use tools, access files, browse networks, write memory, and execute scripts, security has to follow the action path, not just the text prompt.
Secrets, config files, and local credentials are exposed by reads and tool outputs, not only by prompts.
Agents can install packages, run scripts, modify files, change permissions, or reach external networks.
Poisoned memory, modified skills, shell scripts, and hooks can survive beyond the current request.
Track prompts, tool calls, file intents, observed effects, artifacts, risk tags, and lineage in a queryable provenance graph.
Return allow, ask, or deny before tool execution; inspect assembled script content at execution time.
Use the same core controls wherever agents touch tools, files, credentials, memory, or network paths.
Crate plugs into agent execution paths, records evidence locally, and turns policy into action before the tool call completes.
Prompts, tool calls, file intents, observed effects, commands, artifacts, and network targets.
Block risky reads, writes, egress, destructive commands, poisoned memory, and dangerous scripts.
Give security and platform teams timeline evidence for review, escalation, and incident handling.
Query lineage across sessions, requests, artifacts, alerts, and risk tags.
Connect policy, identity, alerting, SIEM, code hosts, agent gateways, and internal platforms.
Crate starts where agent risk becomes concrete: code workspaces, shell access, files, tools, memory, skills, and external network paths.
Crate combines hook-level intent, filesystem and process observations, artifact provenance, and policy decisions into one enforceable runtime graph.
Keep Claude Code and Codex-style agents away from secrets, dangerous scripts, poisoned memory, and destructive commands.
Apply policy, alerting, and evidence to agents working across code, tools, files, and internal systems.
Integrate runtime enforcement into existing systems, MCP gateways, code hosts, identity, and incident response workflows.
It protects agent execution paths: tools, shell commands, file access, memory artifacts, skills/plugins, network targets, and resulting artifacts.
Teams building or adopting agents with access to code, credentials, files, memory, tools, or networked systems.
Prompt guards focus on input text. Gensee Crate watches what agents do to the machine and enforces policy before risky tool calls proceed.
It turns runtime evidence into enforceable decisions, so teams can prevent dangerous actions and keep a provenance trail when they need to investigate.
Crate is designed to connect with existing policy, identity, alerting, code-hosting, incident-response, and agent-platform workflows.
Claude Code is the current local hook focus; Codex, MCP, generic launchers, internal agents, and company-specific integrations are part of the broader direction.
Start with the open-source runtime or talk to us about customer-controlled deployments and integrations.