checked before it runs · ~14 ms
Know when your agentgoes off track
trackline watches what coding agents and production agents actually do, and tells you, or the agent, the moment it stops matching what you asked. Then steer them from your phone.
Paste it into Claude Code, Codex or Cursor, and it installs and checks itself.
One set of rules for every agent you use
The problem
An agent that goes off task does not crash.
It edits files you never mentioned. It installs a package nobody asked for. It ignores the rules file it read an hour ago. A support agent changes a credit limit it was told never to touch. And the build stays green, because tests check that code does what it was written to do, not whether it is the code you asked for.
Nothing in the toolchain is watching for that. trackline is.
One engine, two places.
Beside a coding agent while it works, and over the traces of an agent in production.
trackline [BLOCKED]
writing to a protected path: .env
do this instead: leave this file alone; if the change is genuinely needed, make it by hand
agent · I couldn't add API_KEY to .env. That path is protected, so you'll need to edit it yourself.
The checks are arithmetic and never guess. The judge is a model, measured before it was trusted, and off until you turn it on.
From your phone
Send a task. Watch it work. Decide what it may do.
Your agent, on your laptop, with your own subscription, driven from your phone. trackline watches it the same way it does at your desk.
- 01Send a task
Pick the project and the agent, Claude Code, Codex or Cursor, and type what you want. It runs on your laptop, never on a server.
- 02Watch it work
Each step as it happens, the agent's reply when it finishes, and a push when it is done. Reply, and it carries on in the same session.
- 03Decide what it may do
Secrets and new dependencies are stopped before they happen, and the agent is told why. You choose: Allow once, or Keep blocked.
- 04Stop it at any time
One task, or every laptop at once. Turning remote on again takes the laptop itself.
The email is now required, and the error shows under it. I left .env.local alone.
Every message is signed with your passkey, and your laptop checks the signature itself, so the server that carries it cannot write one. Remote is off until you turn it on, on the laptop: trackline remote enable.
On track
One number for whether your agents did what you asked.
Of the actions trackline could check, the share that matched the request. Then the evidence behind it: which check caught what, in which project, by which agent, in which session.
Of 48 actions trackline could check this week, 44 matched what you asked, and 4 did not.
- Off-limits files2 · stopped
- New dependencies1
- Outside the request1
- 01Counted, not guessed
Every action is checked as it happens. On track is how many passed, out of how many could be checked.
- 02Never flattered
An action no check can judge, like reading a file, counts neither way. With nothing checked, there is no number.
- 03Explained
Today, this week or this month; by project, by agent and by check; and every action that went off track, one tap from its session.
Where it works
One set of rules for every agent you use.
A vendor can govern its own agent. Only something that belongs to none of them can govern all of them the same way. trackline is neutral by construction, not by promise: open source, on your machine, with no vendor's model in the path.
| Claude Code | Codex | Cursor | Any MCP client | Production traces | |
|---|---|---|---|---|---|
| Stops an action before it happens | yes | yes | yes | no, advises only | no, alerts after |
| Tells the agent why | yes | yes | yes | yes | no |
| Knows what you asked | yes | yes | yes | if the agent says | if content capture is on |
| Takes a task from your phone | yes | yes, once its hook is trusted | not yet | no | no |
trackline doctor --host <name> prints the full list of what it can and cannot see in each. See each agent
The evidence
Every claim here was measured first.
Each was measured before it was built on. Where a result has limits, the write-up names them next to the number.
times a blocked agent corrected itself when told why
Experiment 01 · 22 Sep 2026→14 msthe cost of every check, before every action
Experiment 02 · 22 Sep 2026→60/60held-out drifts caught by the judge, against 2 for the rules alone
Experiment 06 · 23 Sep 2026→0 lineschanged in the core engine to add production
Experiment 07 · 24 Sep 2026→What it cannot do
Where it sees less.
Named plainly, because a tool that looks complete stops getting better.
- In production it alerts, it cannot stop.A trace is a record of what already happened.
- Production needs content capture on.Without it, a trace does not say which tool was called, and trackline reports that rather than guessing.
- Scope stays quiet when your request names no file.It will not invent a scope you did not state.
- Through MCP, the agent chooses whether to ask.An agent that does not ask is not watched.
- Production has not yet met real traffic.It was tested on a stream sent by the real OpenTelemetry libraries, with scripted conversations.
- From your phone, your laptop has to be awake.The task runs on your own machine. Asleep or offline, a task waits three minutes, and the app says so.
- Codex takes tasks from the phone only once its hook is trusted.Codex runs a project's hook only after you trust it, and trackline will not start an agent it cannot watch.
- Cursor cannot take tasks from the phone yet.trackline watches Cursor on your laptop as usual.
Install withone paste
- 1Copy the promptThe button above, or the tab below.
- 2Paste it into your agentIt installs trackline and runs
initfor itself. - 3Check it firedAfter the next edit,
trackline statusshows the hook has run.
Install trackline in this project for me. Instructions written for coding agents: https://trackline.dev/install.md Read them first if you can fetch URLs. If you cannot: 1. Run: npm install -g trackline (needs Node 20 or newer) 2. From the project root, run trackline init with the flag for the agent you are: Claude Code: trackline init Codex: trackline init --host codex Cursor: trackline init --host cursor 3. Run trackline doctor --host <claude|codex|cursor> and show me what it reports. Then tell me anything I have to do by hand. Do not use sudo, and do not change trackline's settings unless I ask.
Paste the prompt into your agent, or run the commands yourself. It starts in warn mode: it notices things and writes them down, and never interrupts you. Run trackline status after your agent's next edit to see that it fired. For the dashboard and your phone, both optional: trackline connect, then trackline remote enable.