Guardian

Guardian watches your AI traffic and estate, then recommends what to do next. Nothing enters Work until your team approves it.

What Guardian does

Guardian is always-on detection and response for the AI you already run through Intertrace. It reviews agents, models, tools, and MCP activity on a schedule — and again when something high-risk shows up.

You get a short list of recommended actions, each with evidence. Guardian does not open tickets for you.

How to use it

  1. 1

    Send traffic through Intertrace

    Point a client at Intertrace (Quickstart). Guardian reviews what already appears in Traffic and Estate.

  2. 2

    Open Guardian

    In the dashboard, open Guardian. You will see recent reviews, recommended actions, and when the next review is due.

  3. 3

    Decide on each recommendation

    Approve to create a finding in Work. Dismiss it if it is noise. Every finding you create is audited like any other item in Work.

  4. 4

    Run a review now (optional)

    After a deploy or a spike in Events, run a review immediately. Scheduled reviews keep going either way.

From a recommendation to Work

Live traffic can already raise findings on its own. Guardian is the always-on review: it groups related risk and proposes the next action.

When you create a finding from a recommendation, it lands in the same Work queue your team already uses.

What stays with your team

Guardian recommends. Your team decides.

  • Findings and incidents stay manual. Intertrace does not open an incident for every event — see Findings & incidents.
  • Production policy does not change until an authorized person approves — including applying a policy, disabling a tool, or blocking an MCP server.
  • Guardian does not replace Estate, Traffic, Work, or Policies. It watches the same activity and hands approved work to the inbox you already use.

If Guardian is empty

Connect a client (Quickstart) and confirm requests appear in Traffic. Then wait for the next review, or run one now.