One inventory for every managed runtime.
See enrollment, health, uptime, runtime and policy versions, adapter capabilities, group, tags, bounded activity, and observed versus desired state.
convergeddriftconvergedhealthyOne operating view for work-issued Claude Code runtimes: who is connected, what policy applies, where usage accumulates, what changed, and which actions need attention.
4.2M tokeng-r42···2.8M tokeng-r41···1.9M tokeng-r42···1.1M tokeng-r42···See enrollment, health, uptime, runtime and policy versions, adapter capabilities, group, tags, bounded activity, and observed versus desired state.
convergeddriftconvergedhealthyQuarantine a managed runtime, refresh policy, synchronize state, collect diagnostics, or request a graceful restart. Commands are signed, expiring, reason-bound, and returned with a bounded result.
18 / 18completeappliedsignedAttribute model calls and input/output tokens to the tenant and managed runtime, so cost review can happen by team, project, policy, and operating context.
Current managed-preview accounting attributes model calls and tokens. Provider-price reconciliation, enforced dollar budgets, and invoice-grade reporting are being completed with design partners.
approved2 / 218 / 18healthyUse authority-signed desired state for policy revision, grouping, tags, runtime target, quarantine posture, and supported Pilot configuration. Safe state changes use optimistic revisions and record who changed what and why.
Claude Code becomes manageable when policy reaches the native side effect and the evidence reaches the operator.
Map supported Claude tool events into governed process, filesystem, browser, HTTP, trust, message, and file-transfer actions.
Hold an exact action for expiring human consent, then resume it once with a signed, payload-bound approval.
Refresh policy, sync state, collect diagnostics, export receipts, restart, or shut down through signed allowlisted commands.
Connect the employee runtime, called resource, policy revision, decision, approval, result, and receipt in one trace.
Pilot governs actions surfaced through an installed, supported adapter. It does not provide arbitrary remote shell access, capture unrelated tools automatically, or expose local keys and secrets in the console.
Review architecture →Bring your rollout model, provider-billing context, policy requirements, remote-management needs, and evidence obligations.