ADR · DetectionAgent Detection & Response
Beacon
Endpoint inventory & governance
A signed, user-space agent that inventories and governs where agents run.
What it does
A signed, user-space daemon on every machine, with no kernel driver and nothing to break. It inventories the AI layer (agents, CLIs, versions, MCP servers), flags hygiene and exposure, and evaluates policy on every MCP call locally. Monitor first, enforce when you're ready.
- Inventories installed AI tools, versions, and the MCP servers they're wired to.
- Flags hygiene and exposure: down-level tools, unpinned MCP servers, secrets in config.
- Evaluates policy on every MCP call at the endpoint, where the call originates.
Where it fits
One module of the Beacon platform.
Beacon works alongside the rest of Alyria — prevention and detection for every AI agent your people run, tied together by one policy engine and one signed audit chain.
ObservatoryCloud consoleLyraPolicy-as-codeConstellationMesh + shared memorySpectraTelemetryUmbraAgent secrets
See how the whole platform fits togetherPut Beacon to work.
Deploy Beacon read-only and see how Beacon fits at the endpoint, under your keys.