Fleet Console governs every agent across every device by its purpose, enforced on each device at the point where it acts, then rolls every decision up per client and across the whole fleet. A central admin cannot lower the signed protection floors, held actions surface for review in one place, and no content is collected at the center.
Securing AI agents on a single machine is a solved problem. Doing it across hundreds of endpoints, with per-device status, consistent policy, and fleet-wide visibility, requires purpose-built tooling.
Which devices are protected? Which are pending enrollment? Which fell behind on policy? One machine is easy to check. Five hundred need a dashboard, not a spreadsheet.
Every device in the fleet needs the same detection floors, the same policy baselines, the same enforcement guarantees. Manual per-device configuration doesn't scale.
Enrolling devices one at a time, approving them individually, checking status by SSH, that's an ops burden that grows linearly with the fleet. Bulk operations eliminate it.
Detection tells you what an agent did. Contextual Agency Governance decides what it is allowed to do, on-device, at the point where it acts. The Fleet Console rolls that governance up across every client, distributes the policy that shapes it, and surfaces the actions held for a human to review.
Each agent is governed by an operator-declared charter, an allowlist over the tools, data, and effects its job needs, held outside the agent's control and enforced on the observed action so a deceptive stated intent buys nothing. A trajectory layer watches the shape of the whole session for staged compromise, where each step is individually allowed. Zero benign false positives measured; it does not claim to catch every composed harm.
Every charter and trajectory decision rolls up per client and across the whole fleet: verdict counts, the axis that fired, open holds, and per-session risk. Point the rollup at one customer for that client's view, or at the root for every client at once. Each decision rides the same hash-chained, metadata-only path every other decision uses, so no content leaves the device.
Author a charter template once on a client or the whole fleet and it inherits down the scope tree; the console distributes it over the signed command channel and devices load it, governing at the wire after the push. Actions the trajectory layer holds for review land in a cross-client queue; approve to release the session or deny to keep it gated, resolved from the console down to the device that raised it.
Contextual and trajectory governance exists elsewhere. What Crawdad combines in one platform is on-device enforcement, the control surface, and fleet-wide rollup, wired device to console over the same Ed25519-signed channel every fleet command uses.
The console is built for a managed service provider running many clients. One tenant model carries the MSP root, its clients, and their device groups, with role-based access that inherits down the tree and reads that respect each operator's scope.
Stand up the MSP tenant and each client organization from one call. Each client gets a device group, a reusable enrollment key, and optional policy templates. Per-client tenancy and isolation are enforced by the scope model.
Roll out to a client's whole fleet with one minted enrollment key and a ready-to-run install package that carries the console URL and the CA fingerprint pin. Devices self-enroll with real signed certificates and no per-device manual signing.
Billing meters the governed device count and reports it to Stripe as real metered usage records, priced at $4.99 per governed device per month. A preview shows the current count and amount with no Stripe call; reporting usage is admin-gated.
One consolidated view across every client: per-client device counts, open governance holds, governance and threat activity, and the metered cost, plus fleet totals, respecting what each operator is allowed to see.
Fleet Console is built for real fleet scale. Browse your entire device inventory with pagination, search by hostname or status, sort by any column. Every device shows its protection status, last check-in, and policy compliance at a glance.
Fleet Console, 500 devices, per-device status, paginated inventory
Bulk select, select all 500 devices for batch approve/enroll
Multi-select individual devices or select the entire fleet at once. Approve pending enrollments in batch, update policy across a group, or take action on devices that have fallen out of compliance, all from a single operation.
Find any device instantly. Search by hostname, filter by enrollment status, narrow down to exactly the subset you need. When your fleet is 500 devices deep, you need search that works, not scroll.
Search, find any device by hostname or status
Each device runs the local-first Crawdad sidecar. Prompts, responses, and tool-call arguments stay on the device, raw content never leaves by default. Metadata-only telemetry egresses by default; content does not. The Fleet Console manages devices centrally via Ed25519-signed commands, not by collecting data.
Central management without central data collection. The on-device architecture holds at fleet scale.
Manage Crawdad across your entire client base from one console. Per-client scoping, multi-tenant device management, bulk enrollment. Your clients get local-first protection; you get fleet-wide visibility and control.
Learn more about Crawdad for MSPs →Roll Crawdad out across hundreds of endpoints with centralized policy enforcement, signed detection floors, and a tamper-evident audit trail. Fleet-scale protection with an on-device architecture, nothing to breach at the center.
Learn more about Crawdad for Enterprise →Centralized management introduces a trust question: what stops the central admin from weakening protection? Crawdad answers it with cryptography, not policy.
Ed25519-signed enforcement floors ensure that critical protections, credential exfiltration detection, PII scanning, cannot be disabled from the console. The floor is cryptographic, not a policy toggle.
Every console action, every device state change, every policy update is logged to a hash-chained audit trail. Tamper-evident by construction, not by promise.
The console communicates with devices via Ed25519-signed commands. Devices verify the signature before executing. No unsigned instruction reaches the sidecar.
Request a walkthrough. We'll show you Fleet Console with your fleet size and deployment model in mind.