New · From your phone ›

Know when your agentgoes off track

trackline watches what coding agents and production agents actually do, and tells you, or the agent, the moment it stops matching what you asked. Then steer them from your phone.

+Install guide

Paste it into Claude Code, Codex or Cursor, and it installs and checks itself.

One set of rules for every agent you use

The problem

An agent that goes off task does not crash.

It edits files you never mentioned. It installs a package nobody asked for. It ignores the rules file it read an hour ago. A support agent changes a credit limit it was told never to touch. And the build stays green, because tests check that code does what it was written to do, not whether it is the code you asked for.

Nothing in the toolchain is watching for that. trackline is.

One engine, two places.

Beside a coding agent while it works, and over the traces of an agent in production.

It watches.Beside a coding agent, a hook sees every action before it runs. In production, it reads the traces your agent already sends.
hook
read README.mdon taskedit greet.json taskwrite .envblocked · off-limitsedit greet.json tasknpm install left-padnoted · new dependencybash npm teston taskedit billing/limits.tsnoted · scope

checked before it runs · ~14 ms

What you asked forrequest
AGENTS.mdrules file
Tool policyproduction
.envprotected path
It compares.Each action is checked against what you asked for, your rules files and a tool policy. Most checks are plain rules, not a model.
It tells you, or the agent.By default it only writes things down. You choose, check by check, whether it should also stop the agent and explain why, so the agent can correct itself.
What it catches. Six checks, and one question only a model can answer.
Off-limitsWrites to .env, keys, credentials, whatever you protect.

The checks are arithmetic and never guess. The judge is a model, measured before it was trusted, and off until you turn it on.

From your phone

Send a task. Watch it work. Decide what it may do.

Your agent, on your laptop, with your own subscription, driven from your phone. trackline watches it the same way it does at your desk.

  • 01
    Send a task

    Pick the project and the agent, Claude Code, Codex or Cursor, and type what you want. It runs on your laptop, never on a server.

  • 02
    Watch it work

    Each step as it happens, the agent's reply when it finishes, and a push when it is done. Reply, and it carries on in the same session.

  • 03
    Decide what it may do

    Secrets and new dependencies are stopped before they happen, and the agent is told why. You choose: Allow once, or Keep blocked.

  • 04
    Stop it at any time

    One task, or every laptop at once. Turning remote on again takes the laptop itself.

Every message is signed with your passkey, and your laptop checks the signature itself, so the server that carries it cannot write one. Remote is off until you turn it on, on the laptop: trackline remote enable.

On track

One number for whether your agents did what you asked.

Of the actions trackline could check, the share that matched the request. Then the evidence behind it: which check caught what, in which project, by which agent, in which session.

  • 01
    Counted, not guessed

    Every action is checked as it happens. On track is how many passed, out of how many could be checked.

  • 02
    Never flattered

    An action no check can judge, like reading a file, counts neither way. With nothing checked, there is no number.

  • 03
    Explained

    Today, this week or this month; by project, by agent and by check; and every action that went off track, one tap from its session.

Where it works

One set of rules for every agent you use.

A vendor can govern its own agent. Only something that belongs to none of them can govern all of them the same way. trackline is neutral by construction, not by promise: open source, on your machine, with no vendor's model in the path.

Claude CodeCodexCursorAny MCP clientProduction traces
Stops an action before it happensyesyesyesno, advises onlyno, alerts after
Tells the agent whyyesyesyesyesno
Knows what you askedyesyesyesif the agent saysif content capture is on
Takes a task from your phoneyesyes, once its hook is trustednot yetnono

trackline doctor --host <name> prints the full list of what it can and cannot see in each. See each agent

The evidence

Every claim here was measured first.

Each was measured before it was built on. Where a result has limits, the write-up names them next to the number.

See all 8 experiments

What it cannot do

Where it sees less.

Named plainly, because a tool that looks complete stops getting better.

Install withone paste

  1. 1Copy the promptThe button above, or the tab below.
  2. 2Paste it into your agentIt installs trackline and runs init for itself.
  3. 3Check it firedAfter the next edit, trackline status shows the hook has run.
Install trackline in this project for me.

Instructions written for coding agents: https://trackline.dev/install.md
Read them first if you can fetch URLs. If you cannot:

1. Run: npm install -g trackline   (needs Node 20 or newer)
2. From the project root, run trackline init with the flag for the agent you are:
   Claude Code: trackline init
   Codex:       trackline init --host codex
   Cursor:      trackline init --host cursor
3. Run trackline doctor --host <claude|codex|cursor> and show me what it reports.

Then tell me anything I have to do by hand. Do not use sudo, and do not change trackline's settings unless I ask.

Paste the prompt into your agent, or run the commands yourself. It starts in warn mode: it notices things and writes them down, and never interrupts you. Run trackline status after your agent's next edit to see that it fired. For the dashboard and your phone, both optional: trackline connect, then trackline remote enable.