mTLS between components
Mutual TLS on every internal hop; no plaintext control traffic.
● enforcedSelf-hosted · Vendor-neutral · Open-core
Context, resources, sessions and identities in one self-hosted plane: Claude Code at the deepest level, Codex and Grok Build alongside — and open to any other model or provider you run.
Your agents get what they need to do real work; you keep the granular permissions, policy, budgets and audit evidence to run all of it. It complements your agents; it does not compete.
The product tour
Every surface, with real console screenshots and an honest account of what is live today.
Read/write access and least-privilege drift — the differentiator.
Inspect observed session actions, models, tokens, costs, and event history, with governed work items and handoffs. Goals depend on the reporting source; computed task progress and the complete operating workflow are not yet verified.
One-click estate stop, dual-control recovery.
Control status and sealed evidence — not a certification.
See, attribute and govern model spend.
Real screenshot
17 genuine views of the Olivares console, captured from the product with example data.
Discover · 01 / 05
No proxy, no agents to babysit. Olivares watches your infrastructure and inventories every agent, session, model and MCP — with the surfaces each one reads and writes.
data-export-job holds an unreviewed write to prod-postgres — least-privilege drift, surfaced the moment it appears.
Govern · 02 / 05
Write policy as code and watch it land on the map. The unreviewed write to your production database becomes a denied, least-privilege path.
Pin the export job to read-only on the production database; block writes.
enforcement● enforcing
Cost · 03 / 05
Every dollar tied to the agent, model and team that caused it — with budgets and trends your finance team can act on, not guess at.
| Agent | Model | 30d | Trend | % total |
|---|---|---|---|---|
| claude-deploy-bot | claude-opus-4-8 | $1,860 | 22.1% | |
| data-export-job | magistral-small | $1,240 | 14.8% | |
| support-rag-agent | gpt-5.5 | $980 | 11.7% | |
| infra-copilot | claude-opus-4-8 | $880 | 10.5% | |
| billing-reconciler | claude-sonnet-4-6 | $720 | 8.6% | |
| qa-runner | gpt-5.4-mini | $180 | 2.1% | |
| +208 more agents | $2,540 | 30% | ||
Audit · 04 / 05
Every access in a tamper-evident, hash-chained ledger — filter it, replay it, and export it as evidence your auditors accept.
Security & Compliance · 05 / 05
mTLS, an append-only ledger and policy enforced at access time — mapped to the frameworks your auditors ask about.
Mutual TLS on every internal hop; no plaintext control traffic.
● enforcedEvery view and change hash-chained and tamper-evident.
● activePolicy enforced at access time — blocked, not just logged.
● enforcedPassive discovery from a minimally-privileged, read-only collector.
● active| Framework | Access control | Audit trail | Risk mgmt | Data governance | Coverage |
|---|---|---|---|---|---|
| EU AI Act | mapped | mapped | mapped | mapped | 96.9% |
| NIST AI RMF | mapped | mapped | mapped | partial | 98.6% |
| ISO 42001 | mapped | mapped | in progress | mapped | 97.4% |
| SOC 2 | mapped | mapped | partial | mapped | 98.4% |
How it works
A single container or binary on your own infrastructure. No account, no cloud dependency, no mandatory calls home.
Olivares AI passively finds every agent, session, MCP and model already running — no mandatory proxy.
It builds the access graph: what each agent can reach and what it actually touches, read versus read/write.
Set policy, watch for drift and export audit evidence. Visibility becomes control as your estate grows.
Open source
Olivares AI is open-core under AGPL-3.0. The complete product is in the public repository, tagged and signed since v26.8.0 — to run on your own infrastructure, inspect every line, and keep your data where it belongs. A commercial license and a dedicated enterprise tier are available when your organization needs them.
The complete product, self-hosted, free — no feature gates on the core.
Not tied to any single AI vendor, identity provider or cloud.
Olivares makes no mandatory calls home and runs in isolated, regulated networks. Commercial air-gap delivery is scoped under Enterprise.
Sponsorship sustains the development, integration and updates of Olivares AI; it is not a support contract and buys no priority.
Deploy Olivares AI on your own infrastructure and get the access map your platform and security teams have been asking for.