Control Tower

Agent Fleet Dashboard
Checking Warp…
Enterprise estate

Needs review

View all deviations →
Observed behaviorAgent and contextResponseLast seen

Agent runtimes

Observed agents by runtime
View agents →

Recent relationships

Selected activity, not the full topology
Explore graph →
STATUS
AGENT-TO-AGENT ACTIVITY who's talking to whom · click an agent
Loading activity…
conforming   deviation   egress
Tags are set on each agent when it starts, and are how you write group policy. Filter the fleet by tag above.

Deviations

an agent did something it never declared
TYPE
SOURCE

By type · open

AgentWhat happenedDeclared → seenSeverityLast seen
Every row acts on new traffic, not the flow that triggered it, Maya reports and contains, it doesn't retroactively unsend. Budget figures are volume estimates, not exact token counts.

Destinations

named groups your reachability policies target
GroupMatchersExpands to nowVer
Loading destinations…
Destination groups are reusable allow/deny targets. Provider catalogs (ALL-LLMs, per-provider) are predefined and read-only; add your own from Network · Name · Catalog · Semantic · Special matchers. Expands to now resolves each matcher via SNI + CIDR, provider naming is CIDR-confidence (coarse), never rendered exact.

Enforcement

decide what happens, reversible, acts on new traffic
— pkts dropped
Applies to (tags)ActionMembersDroppedPriority
Loading group policies…
Group policy attaches an action to every agent carrying a set of tags, new matching agents inherit it automatically. Enforcing actions ask you to confirm the count first. Actions: watch · alert · block. Removing a policy clears it everywhere.
Auto-block on high-severity deviations
Loading…
▸ Advanced, low-level policy API (power users)
Beyond the tag-group and single-agent controls above, policy can be written directly against the management API, agent-scoped or CIDR-prefix rules via POST /api/v1/policy (see the API docs / your SIEM integration). Day-to-day policy is written by tag group above; most operators never need the raw API. (No in-console rule builder, this describes the API, not a form here.)

Export

emit findings & telemetry to your collector over OTLP
Collector
Export enabled
Status
Export is OTLP telemetry emission (metadata-only by default, payload-blind). It is the outbound half of bring-your-own-judgment, not traffic mirroring.
Escalation audit log
Export feeds your SIEM or judgment engine, findings and telemetry over OTLP, metadata-only by default. This is the SIEM/BYOJ-outbound path.

System

appliance health
Components
Connected Stitches
Deployed software
Destination attribution — all traffic, appliance-wide
Setpoint
Baseline monitor,
pauses LLM assessments only · baseline preserved · cap 20/min always on
Live logs live
Warp · Weaver · Loom · Setpoint
connecting…

Sign in

Maya Console