Every machine runs a different agent setup. One approved baseline ends that.

Skills, sub-agents, rules and hooks decide how an agent behaves, and today every engineer assembles their own. The control plane shows what is actually running, pushes the approved setup from one place, and denies what should not run at all.

app.tetriz.ai / govern / harness
Fleet · against the approved baselineSample data
On baseline82%
Drifted14%
Not reporting4%
18
Skills published
3
Packs denied
214
Machines reporting
What changes

From per-machine folklore, to a setup the org actually agreed on.

Without Tetriz
  • Every engineer assembling an agent setup from scratch
  • A risky skill pack spreading with nothing in its way
  • No way to tell an agreed setup from a drifted one
✓ With Tetriz
  • What is running, on which machines, against the agreed baseline
  • Approved skills, sub-agents and rules pushed from one place
  • Risky packs denied at org level, enforced at install time
What you’ll see

See it, push it, block it.

Fleet compliance
214 machines reportingSample data
On baseline82%
Drifted14%
payments-01
14 skills · 5 sub-agents
On baseline
platform-07
16 skills · 5 sub-agents
Drifted
data-03
12 skills · 4 sub-agents
On baseline
The design

Standardise without slowing engineers down.

A control plane engineers route around is worse than none at all. Three properties keep this one from becoming that.

01

The baseline, not the ceiling

The org-approved harness is the default. Engineers still add their own on top, and the baseline updates when the central library does.

02

Denied at install time

Skills, plugins or rule packs flagged as risky are denied at org level, and the deny list is enforced when someone tries to install one.

03

Published from a vetted base

Admins publish from the same recommendation engine that powers the improvement loop, rather than triaging the public catalogue cold.

This is the one surface in Tetriz that writes anything, and what it writes is harness configuration an admin published — never code, never commits. Access is role-based, and the org baseline is a default engineers build on, not a ceiling.

At org scale

From one engineer's setup to the whole fleet's posture.

The approved baseline arrives on one machine already working; the same signal rolls up to what the org is actually running, without anyone reading a line of code.

Contributor
Bruce Wayne
wayne-repo · on baseline
Skills
14
Sub-agents
5
Drift
0
Fleet
214
machines reporting
18
skills published
3packs denied
Against baseline
On baseline
176
Drifted
30
Not reporting
8
Drift by team
Platform
14
Payments
10
Data
6
Recent denials
1
shell-runner@2.1
Unscoped shell access · 6 Aug
denied
2
repo-sync-agent
Known vulnerability · 2 Aug
denied
3
auto-commit@0.9
Writes without review · 28 Jul
denied
FAQ

Questions leaders ask.

Everything wrapped around the AI agent that shapes how it behaves: skills, sub-agents, plugins, hooks, and the CLAUDE.md, AGENTS.md or Cursor rules file the engineer has installed. It is why the same tool produces different output in different hands.

Yes, and it is the one place in Tetriz that writes anything. What it pushes is harness configuration an admin has published: skills, sub-agents and rules. It cannot modify code and it cannot push commits.

Yes. The org-approved harness is the default baseline, not a ceiling. Engineers add their own on top, and the baseline refreshes when the central library is updated. A control plane that froze everyone's setup would just get worked around.

Packs flagged as risky during evaluation are denied at org level, and that denial is enforced at install time. It means a vulnerable sub-agent gets blocked everywhere at once instead of being chased repo by repo.

Admins publish from a vetted base fed by the same recommendation engine behind the improvement loop, pre-filtered against the org's security posture. The alternative is triaging the public catalogue cold, which is why most orgs never start.

Drivers is the visibility layer: what is installed, what gets used, and where it conflicts. The control plane is the action on top of it: publish, push, deny. Same data, different verb.