TraceFence

Agent ControlAgent 控制

Separate product surface独立产品页面

Secure Execution and Plugin Permission Control for Local AI Agents

为本地 AI Agent 提供安全执行与插件权限控制

TraceFence Agent Control provides runtime permission isolation, signature verification, and activity monitoring for local AI agents and 52 modular plugins.

TraceFence Agent Control 为本地 AI Agent 和 52 个模块化插件提供运行时权限隔离、签名验证与活动监控。

This page covers the agent-control category separately from Codex media cleanup. The current catalog, adapter capabilities, and local connection boundary remain inspectable before you choose an action.

本页面将 Agent 控制与 Codex 媒体整理分开说明。当前目录、适配器能力和本地连接边界都可在操作前查看。

Permission-aware plugin sandbox有权限边界的插件沙箱

TraceFence separates plugin lifecycle information from the host. Before installation, the catalog exposes the declared permission list, package metadata, version, and integrity fields for review.

TraceFence 将插件生命周期信息与主程序分开。安装前,目录会展示声明的权限列表、包元数据、版本与完整性字段供检查。

  • 52 plugins in the public catalog个公开目录插件
  • 0 declared permissions for Codex Media Cleanup 1.0.2Codex 媒体整理 1.0.2 声明权限数
  • 14 current catalog revision当前目录修订号

Read the signed catalog source of truth →

Activity and approval visibility活动与审批可见

Agent Monitor exposes local status and activity for supported agents. Agent Guard reviews local operations, approvals, and safety events. These are local product surfaces, not a promise that every adapter exposes the same controls.

Agent Monitor 展示支持的 Agent 本地状态与活动;Agent Guard 检查本地操作、审批与安全事件。这些是本地产品能力,不代表所有适配器都有相同控制项。

Capability contract

TraceFence shows an action only when the adapter reports a real local control path; display-only sessions stay read-only.

How the local control boundary works本地控制边界如何工作

01 · Pair

Pair TraceFence Sentinel with the Mac over LAN, Tailscale, VPN, or another tunnel you operate.

02 · Inspect

Review the agent, adapter, requested action, plugin version, and declared permissions before responding.

03 · Act

Approve, deny, launch, interrupt, resume, or terminate only when the local session exposes that control path.

04 · Recover

Keep plugin updates and rollback paths visible, while preserving user ownership of the Mac and its network.

Decision answers

Local control without capability guesswork.

Four direct answers for teams evaluating local AI agent management and plugin permissions.

What does TraceFence Agent Control manage?

It manages supported local AI agent sessions, plugin lifecycle information, approval paths, and activity visibility from the Mac host and paired iPhone.

Are all TraceFence plugins available with the same permissions?

No. Permissions are exposed per catalog entry, and the public catalog is the authority for the current version and permission declaration of each plugin.

Can TraceFence control every local AI agent?

No. Available actions depend on the installed CLI, hook, adapter, and session ownership; integrations without a real control path remain read-only.

Does Agent Control require a TraceFence cloud relay?

No. TraceFence Sentinel connects to a paired Mac over LAN, Tailscale, VPN, or another user-operated tunnel rather than a TraceFence-hosted agent relay.