Your agents are already acting across your fleet. Govern what every one of them does.

Fleet Console governs every agent across every device by its purpose, enforced on each device at the point where it acts, then rolls every decision up per client and across the whole fleet. A central admin cannot lower the signed protection floors, held actions surface for review in one place, and no content is collected at the center.

Talk to Us → See the Console
Crawdad Fleet Console, centralized device management across your fleet

One device is straightforward. A fleet is a different problem.

Securing AI agents on a single machine is a solved problem. Doing it across hundreds of endpoints, with per-device status, consistent policy, and fleet-wide visibility, requires purpose-built tooling.

Visibility at scale

Which devices are protected? Which are pending enrollment? Which fell behind on policy? One machine is easy to check. Five hundred need a dashboard, not a spreadsheet.

Consistent enforcement

Every device in the fleet needs the same detection floors, the same policy baselines, the same enforcement guarantees. Manual per-device configuration doesn't scale.

Operational efficiency

Enrolling devices one at a time, approving them individually, checking status by SSH, that's an ops burden that grows linearly with the fleet. Bulk operations eliminate it.

Govern what every agent is allowed to do. Across the whole fleet.

Detection tells you what an agent did. Contextual Agency Governance decides what it is allowed to do, on-device, at the point where it acts. The Fleet Console rolls that governance up across every client, distributes the policy that shapes it, and surfaces the actions held for a human to review.

Charters and trajectory, governed centrally

Each agent is governed by an operator-declared charter, an allowlist over the tools, data, and effects its job needs, held outside the agent's control and enforced on the observed action so a deceptive stated intent buys nothing. A trajectory layer watches the shape of the whole session for staged compromise, where each step is individually allowed. Zero benign false positives measured; it does not claim to catch every composed harm.

Rolled up per client and across clients

Every charter and trajectory decision rolls up per client and across the whole fleet: verdict counts, the axis that fired, open holds, and per-session risk. Point the rollup at one customer for that client's view, or at the root for every client at once. Each decision rides the same hash-chained, metadata-only path every other decision uses, so no content leaves the device.

Templates out, holds back

Author a charter template once on a client or the whole fleet and it inherits down the scope tree; the console distributes it over the signed command channel and devices load it, governing at the wire after the push. Actions the trajectory layer holds for review land in a cross-client queue; approve to release the session or deny to keep it gated, resolved from the console down to the device that raised it.

Contextual and trajectory governance exists elsewhere. What Crawdad combines in one platform is on-device enforcement, the control surface, and fleet-wide rollup, wired device to console over the same Ed25519-signed channel every fleet command uses.

Provision, roll out, bill, and reconcile.

The console is built for a managed service provider running many clients. One tenant model carries the MSP root, its clients, and their device groups, with role-based access that inherits down the tree and reads that respect each operator's scope.

Provision a tenant and its clients

Stand up the MSP tenant and each client organization from one call. Each client gets a device group, a reusable enrollment key, and optional policy templates. Per-client tenancy and isolation are enforced by the scope model.

Turnkey rollout

Roll out to a client's whole fleet with one minted enrollment key and a ready-to-run install package that carries the console URL and the CA fingerprint pin. Devices self-enroll with real signed certificates and no per-device manual signing.

Metered billing at $4.99 per device

Billing meters the governed device count and reports it to Stripe as real metered usage records, priced at $4.99 per governed device per month. A preview shows the current count and amount with no Stripe call; reporting usage is admin-gated.

Cross-org rollup

One consolidated view across every client: per-client device counts, open governance holds, governance and threat activity, and the metered cost, plus fleet totals, respecting what each operator is allowed to see.

500+ devices. One view.

Fleet Console is built for real fleet scale. Browse your entire device inventory with pagination, search by hostname or status, sort by any column. Every device shows its protection status, last check-in, and policy compliance at a glance.

  • Per-device protection status and last check-in
  • Pagination and search across the full device fleet
  • Sort by hostname, status, enrollment date
  • Real-time posture view across the organization
Fleet Console showing 500 devices with per-device status, pagination, and sorting

Fleet Console, 500 devices, per-device status, paginated inventory

Fleet Console bulk selection, select all 500 devices for batch operations

Bulk select, select all 500 devices for batch approve/enroll

Approve, enroll, manage, in bulk.

Multi-select individual devices or select the entire fleet at once. Approve pending enrollments in batch, update policy across a group, or take action on devices that have fallen out of compliance, all from a single operation.

  • Multi-select individual devices or select all
  • Batch approve pending enrollments
  • Fleet-wide policy updates in one operation
  • Filter, then act, target exactly the devices you need

Search, filter, act.

Find any device instantly. Search by hostname, filter by enrollment status, narrow down to exactly the subset you need. When your fleet is 500 devices deep, you need search that works, not scroll.

  • Real-time hostname search
  • Filter by protection status or enrollment state
  • Combine search with bulk operations
Fleet Console search, find devices by hostname or status

Search, find any device by hostname or status

Architecture
┌─────────────────────────┐
 Fleet Console
 signed commands (Ed25519)
└──────────┬──────────────┘
           │
 ┌───────┴───────┐
 │  Device A    │  local sidecar
 │  Device B    │  local sidecar
 │  Device C    │  local sidecar
 │  …          │
 └───────────────┘
raw content stays on device
console manages via signed commands

Central management. No central data.

Each device runs the local-first Crawdad sidecar. Prompts, responses, and tool-call arguments stay on the device, raw content never leaves by default. Metadata-only telemetry egresses by default; content does not. The Fleet Console manages devices centrally via Ed25519-signed commands, not by collecting data.

Central management without central data collection. The on-device architecture holds at fleet scale.

  • Each device runs a local-first sidecar, raw content stays on device
  • Console sends signed commands, not data requests
  • No aggregation risk, nothing to breach at the center
  • Runs fully offline, no telemetry dependency

Fleet-scale security for the teams that need it.

For Managed Service Providers

Manage Crawdad across your entire client base from one console. Per-client scoping, multi-tenant device management, bulk enrollment. Your clients get local-first protection; you get fleet-wide visibility and control.

Learn more about Crawdad for MSPs →

For Enterprise Security Teams

Roll Crawdad out across hundreds of endpoints with centralized policy enforcement, signed detection floors, and a tamper-evident audit trail. Fleet-scale protection with an on-device architecture, nothing to breach at the center.

Learn more about Crawdad for Enterprise →

Fleet management you can verify.

Centralized management introduces a trust question: what stops the central admin from weakening protection? Crawdad answers it with cryptography, not policy.

Signed hard floors

Ed25519-signed enforcement floors ensure that critical protections, credential exfiltration detection, PII scanning, cannot be disabled from the console. The floor is cryptographic, not a policy toggle.

Tamper-evident audit trail

Every console action, every device state change, every policy update is logged to a hash-chained audit trail. Tamper-evident by construction, not by promise.

Signed commands

The console communicates with devices via Ed25519-signed commands. Devices verify the signature before executing. No unsigned instruction reaches the sidecar.

Ready to manage AI security across your fleet?

Request a walkthrough. We'll show you Fleet Console with your fleet size and deployment model in mind.

Request a Walkthrough → Get Started

Get in Touch

Tell us about your needs and we'll follow up.