Govern

Enterprise

The control plane for AI engineering — visibility, governance, verifiable proof and deployment options for agentic work across an org.

Excalibur Core is free and local-first. Excalibur Enterprise adds the control plane a team needs to run a human + agent workforce safely at scale. Every capability is built on the same event stream and run history the CLI already produces — so each has a developer face and a leadership face.

What Enterprise adds

Visibility & ROI

Insights across five lenses — cost · time · usage · quality · governance — filterable by date, team, repo, model, autonomy and work item, with CSV/JSON export and email/Slack digests. Roll-up org → department → team → repo with chargeback, plus budgets with forecasts and alerts.

Governance & risk

A server-side policy engine: model permissions by repo/sensitivity, sensitive-paths → approval, server-side command allowlists, secret DLP, require-tests-before-PR, and budgets enforced mid-run. A Trust Budget lets each developer tune autonomy within the org's ceiling.

Identity & access

SSO (OIDC/SAML — Okta, Azure AD, Google) and SCIM as the primary provisioning path, with automatic deprovisioning. Granular RBAC and multi-tenant teams; views and actions gated by role.

Verifiable quality → Compliance Pack

The typed claims that gate every run (tests_passed, type_safe, no_secrets) aggregate into a signed Compliance Pack — an audit dossier your auditors will accept. Adversarial review runs before a human ever sees the work.

Institutional memory

Knowledge Compounding — a decision memory with evidence weight that survives turnover and makes every future run smarter. Capability Ledger — autonomy earned by real outcomes, under a policy ceiling.

Coordinate humans + agents

Agentic-agile daily & weekly planning with human supervisors, a native kanban (or synced from Linear / Jira / GitHub / GitLab), and approvals from your phone.

Audit & deployment

An immutable audit log exportable to your SIEM, with retention, SOC 2 controls, GDPR/DPA and data residency. Deploy in our cloud, with a hybrid runner in your infra, or fully self-hosted and air-gapped — your source never leaves your environment.

The Workbench

A web control plane on the same event stream as the CLI — one source of truth, fully responsive (approve from your phone): fleet dashboard, Run Workbench (live phases, Monaco diffs, approvals, cost), Approvals, Insights, Audit and the kanban. Because a run is a durable, replayable event stream, remote control is "open this run on your phone and fork/rewind," not just live steering.

Connecting the CLI

The CLI authenticates to Enterprise without leaving your terminal:

excalibur login      # device-auth: opens the browser, binds the CLI to your user
excalibur connect    # pull team models, policies, workflows and defaults
excalibur sync       # push runs & events (opt-in)

Governance is enforced server-side and doesn't depend on running init — corporate models, the merge chokepoint (GitHub/GitLab App + required checks) and runners live behind the control plane. A credential can be distributed by MDM so login is invisible.

Deployment options

ModeWhere runs executeFor
CloudExcalibur-hostedFastest to adopt.
Hybrid runnerYour infra (code stays in)Regulated teams.
Self-hostedYour cluster (Helm)Full control.
Air-gappedOffline, your networkHighest assurance.

Learn more

See the Enterprise overview or book a demo.

Next