SeeAgent operationsx, accounted for
Run your agent fleet from one control room.
See where each agent stands and who changed it, chain agents into workflows a person can join, and replay a session request by request.
One agent · from refusals to replay: 09:12 Refusals rise (support-bot, prompt injection); 09:13 Workflow runs (Refusal trigger); 09:14 Agent quarantined (Reason on record); 09:30 Session replayed (Request by request).
In short
Agent operations in ColossalX is the control room for a fleet of AI agents. It shows posture, violations and spend with the agent named behind each refusal, keeps an append-only history of each agent's state and who changed it, runs workflows a person can join, and replays a recorded session request by request.
An agent misbehaves overnight, and nobody can say what it did or who last changed it.
ColossalX shows the fleet's state, keeps who changed what, and replays the session request by request.
How it works
From a fleet in motion to a replayed request.
One agent that starts to be refused, followed from the control room through a workflow that contains it to the recording that replays what it did.
01 Refusals rise
The control room names the agent behind each refusal.
02 Workflow responds
A workflow quarantines the agent and tells a person.
03 History kept
Lifecycle records who acted: a workflow, a control or a person.
04 Session replayed
The recording shows each request and the decision every gate made.
What you see
The fleet, its history and one replayed session.
The control room shows the fleet's state and the Kill Switch. A recording opens to the decision each gate made on a request, as a timeline rather than video.
- See the fleet
- Read each history
- Chain agents
- Replay a session
Read the detail, step by step4
- See the fleet. One view of posture, violations, spend and the Kill Switch. Fleet tiles count agents by state, and the gap between registered agents and those active in traffic is itself a finding. Beside them sit guardrail coverage, a violations timeline, recent refusals with the agent behind each, and an agent leaderboard you can export.
- Read each history. State changes are kept, with who made them and why. Lifecycle shows where each agent stands and what changed this month, from an append-only history written by the database, naming a person, a control or a workflow as the actor. Governance lists the controls in force, how the fleet behaved against them, and a trail of changes and containments.
- Chain agents. Workflows ask agents, branch on answers and wait for a person. Design a workflow on a canvas: ask an agent, branch, wait for approval, quarantine an agent, raise an incident, trip the Kill Switch or notify. It can start manually, on a schedule, on an agent event or on a gateway refusal. Each agent step runs through the gateway as that agent.
- Replay a session. Record an agent for a set time, then replay it. Start a recording on an agent, or on your own privileged session, with a purpose and a stop time. Replay merges gateway requests, tool calls, lifecycle events and behaviour alerts in order. Open a request to see each gate's decision and, if you chose to keep them, the prompt and the reply.
An illustrative agent control room: one agent running and one quarantined, the Kill Switch on standby, and a session replay with a strip of recorded events and one request opened to the decision each gate made on it: allowed, redacted and refused.
3notes
- Fleet state, and the Kill Switch
- A session, replayed request by request
- The decision each gate made
How it connectsx, accounted for
Where agent operations lead next.
The control room reads the controls around it, and what it shows leaves a record.
The control room shows its state and scope, and a workflow step can trip it.
Governance shows which profiles carry a rule the request path actually reads.
Each lifecycle entry links to its agent, so a change leads to its owner.
A workflow can quarantine an agent; its trust zone and grants stay on record.
Honest by design
What it does, and what it does not.
Control room · stated plainly: Replay Event timeline, not video; Request bodies Kept only if you chose; Workflow steps A fixed set, no code step; Traffic figures Agents on the gateway only. States its own limits.
What it does not do
x, not measured
Replay is an event timeline, not video, and keeps prompts and replies only if you choose to.
All 4 limits
- Workflows use a fixed set of step types; there is no arbitrary code or HTTP step.
- An agent step is refused for an agent that is quarantined or not approved.
- Traffic figures cover agents that call through the gateway; the rest are registered only.
How we know
- Lifecycle history is append-only and names who acted: a person, a control or a workflow.
- Each workflow agent step runs through the gateway as that agent, so its controls still apply.
- Governance counts a control as in force only when a rule on the request path reads it.
- A replayed request shows the decision each gate made on it: allow, flag or block.
Questions
Questions buyers ask
What is an AI agent control room?
An AI agent control room is one place to run a fleet of agents: how many are active, suspended or quarantined, what the guardrails refused, what the fleet spent and what state the kill switch is in. In ColossalX it also names the agent behind each refusal, so a spike has an owner to ask.
How do you audit what an AI agent did?
Start with its history and its recording. Lifecycle keeps an append-only record of each state change and who made it, and governance lists configuration changes and violations with who and when. For a closer look, a session recording replays requests, tool calls and alerts, with the decision each guardrail made on each request.
Can you replay an AI agent session?
Yes. Start a recording on an agent, or on your own privileged session, with a purpose and a stop time. Replay is an event timeline rather than video: gateway requests, tool calls, lifecycle events and behaviour alerts, merged in order. Open a request to see the model, each gate's decision and, if you kept them, the prompt and reply.
Can a workflow contain an agent without a person?
Where you design it that way. A workflow can start on a gateway refusal or an agent event, then quarantine the agent, raise an incident, trip the kill switch or notify people. It can also wait for approval, and an approval can require someone other than the person who started the run. A workflow acts with the permissions of whoever activated it.
What does "enforced" mean for a guardrail profile?
A profile counts as enforced only when it carries at least one rule that a step on the request path actually reads. The governance view lists each profile as enforced or declared only, with how many of its rules are read, beside the share of agents free of violations and a trail of who changed what.
Related
Where to look next.
-
Detection and response
Containment and the ColossalX Kill Switch
-
Agent access, earned
Gates, zones, promotion and expiring grants
-
AI inventory and agent map
Agents from code and traffic, on one map
Next step
Know your x, from one room.
See your own fleet, its history and one replayed session, with your own agents.
- 01Tell us what you run
- 02See the four verbs on it
- 03Decide where to start