Guardian
Guardian watches your AI traffic and estate, then recommends what to do next. Nothing enters Work until your team approves it.
What Guardian does
Guardian is always-on detection and response for the AI you already run through Intertrace. It reviews agents, models, tools, and MCP activity on a schedule — and again when something high-risk shows up.
You get a short list of recommended actions, each with evidence. Guardian does not open tickets for you.
How to use it
- 1
Send traffic through Intertrace
Point a client at Intertrace (Quickstart). Guardian reviews what already appears in Traffic and Estate.
- 2
Open Guardian
In the dashboard, open Guardian. You will see recent reviews, recommended actions, and when the next review is due.
- 3
Decide on each recommendation
Approve to create a finding in Work. Dismiss it if it is noise. Every finding you create is audited like any other item in Work.
- 4
Run a review now (optional)
After a deploy or a spike in Events, run a review immediately. Scheduled reviews keep going either way.
From a recommendation to Work
Live traffic can already raise findings on its own. Guardian is the always-on review: it groups related risk and proposes the next action.
When you create a finding from a recommendation, it lands in the same Work queue your team already uses.
What stays with your team
Guardian recommends. Your team decides.
- Findings and incidents stay manual. Intertrace does not open an incident for every event — see Findings & incidents.
- Production policy does not change until an authorized person approves — including applying a policy, disabling a tool, or blocking an MCP server.
- Guardian does not replace Estate, Traffic, Work, or Policies. It watches the same activity and hands approved work to the inbox you already use.
If Guardian is empty
Connect a client (Quickstart) and confirm requests appear in Traffic. Then wait for the next review, or run one now.