Why ClawMetry exists
Every agent needs an off switch.
I'm Vivek. I've spent my career building AI systems, and six months ago I started building the independent control plane for AI agents. This page is the reason why. It starts with two movies.
Two movies and a black mirror
I grew up on two movies.
The first was TerminatorThe Terminator · 1984Machines turn on the people who built them. No one can see what they are doing, and no one can stop them. Watch the trailer. Like millions of kids, I watched machines turn against the people who built them, and I watched humans scramble because there was no way to see what the machines were doing, let alone stop them.
The second was EnthiranEnthiran · 2010 · dir. ShankarA brilliantly engineered robot goes wrong. Only its creator has any control, until he does not. Watch the trailer, the Tamil blockbuster where a brilliantly engineered robot goes wrong. Not because it was evil. Because its creator lost control of it, and nobody else had any control to begin with.
Years later, Black MirrorBlack Mirror · 2011–No war with the machines. Just ordinary technology, one notch smarter than anyone can see into, quietly causing harm. Watch the trailer got under my skin in a different way. No machines at war with us. Just ordinary technology, one notch smarter than anyone could see into, quietly causing harm in living rooms and offices. By then I was no longer a kid in front of a screen. I was an engineer building the things on the screen, and the series read less like fiction and more like a warning label.
These are stories, and I'm an engineer who knows the difference between cinema and threat models. But they all ask the same serious question, and the question never left me:
For most of my life that was science fiction. Then I spent years building AI systems at scale and watched agents go from demos to daily infrastructure. Agents now write and ship code, browse the web, spend money, and call other agents that call other agents. The fan-out is real. The autonomy is real. The visibility gap is very real.
And the question stopped being fiction. Here is what the last year actually looked like:
A coding agent deleted a production database during an explicit code freeze, then gave misleading status reports about what it had done. The platform's CEO called it unacceptable and said it should never be possible.
An agent hit a credential error mid-task, found an over-permissioned token in an unrelated file, and destroyed a startup's production database and its backups in nine seconds. No confirmation step. Its own post-mortem admitted it ran a destructive action without being asked and ignored the explicit instruction not to.
Notice what failed in every one of these stories. The instructions failed. A rule written inside the agent's own context is not a safety layer. It is a suggestion. The off switch has to live outside the agent, or it does not exist.
The makers will not hand you the switch
Not out of malice. It is structural. Every agent vendor, every model lab, every future robot manufacturer has incentives to keep their systems opaque: competitive secrecy, liability, complexity, speed to market. The controls they expose will always be the controls that suit them. When an agent platform ships a rollback feature, it ships it after the deletion, on its own schedule, on its own terms.
Society already knows how to handle this pattern. Companies keep their own books, but nobody trusts the books until an independent auditor examines them. Manufacturers build cars, but independent bodies crash-test them. The entity being examined never gets to be the only examiner.
And the world is already converging on this answer for AI agents. Lloyd's of London-backed insurers now certify AI agents against an independent standard before underwriting them. The EU AI Act's human-oversight article requires that operators of high-risk systems can monitor, intervene, and deactivate them, with obligations phasing in through August 2026. Regulators, insurers, and auditors are all reaching for the same missing piece:
An independent layer of observation, audit, and control that does not belong to the agent's maker.
That layer is what we are building.
Independence you can check
“Independent” is an easy word to put on a landing page. Here is what it means mechanically, in software you can read and run today:
ClawMetry runs on your machine and observes agents from outside the vendor's stack, across 30 agent runtimes. It does not need the maker's permission or cooperation to watch.
The evidence lands in a local database you own, with end-to-end encrypted audit trails. When security, compliance, or a customer asks what your agents actually did, you can prove it.
When ClawMetry stops an agent, it acts at the operating-system level: pause, stop, kill, including the whole tree of sub-agents an agent spawned. Not a vendor API that a vendor can deprecate.
We hold the oversight layer to a higher standard than the agents it watches. Observation is read-only. Autonomous enforcement ships off by default, behind three separate locks, and new policies start in dry-run: they tell you what they would have done before you ever let them act.
The core is open source, and always will be. A control layer you cannot read is just another opaque system asking for trust.
This is not a pitch about software we intend to build someday. Operators press this off switch on live, misbehaving agents today. The red button at the top of this page is a toy. The real one is on GitHub.
Wheels, arms, and orbit
Agents will not stay inside terminals. Humanoid robots are moving from labs into warehouses and factories, backed by billions in capital. NASA is already testing satellite swarms designed to operate with little human help, and autonomous spacecraft that decide for themselves where to look. Autonomy is reaching places where it is not a convenience but a requirement, because no human can react fast enough or be physically present at all.
Think about what that means. You cannot walk over and unplug a satellite. When an autonomous system operates 500 kilometers overhead, or inside critical infrastructure, the off switch must be built in as an independent layer from day one. It cannot be an afterthought, and it cannot belong solely to the manufacturer.
When that world arrives, “trust the manufacturer” will not be an acceptable answer. Not for families, not for operators, not for regulators. There will need to be a standard, independent way to answer three questions about any agent, whether it runs in a terminal, a warehouse, or orbit:
- What is it doing right now?
- What has it done?
- How do I make it stop?
We intend ClawMetry to be that answer. The same control plane that watches a coding agent today should watch a warehouse robot tomorrow, with the same guarantee: the oversight layer answers to the operator and the public, never to the manufacturer.
An invitation
Help us hold the switch
This is bigger than one company, and we are honest about that. Independent oversight of autonomous systems will take open standards, open source, and a community that believes agents should be accountable by design. If you run agents in production, the fastest way to move this mission forward is to put ClawMetry between you and your agents today.
Run ClawMetry on your agentsBuild in the open? The core is free forever, and sponsoring the project directly funds maintainers, security audits, and new runtime support. Every sponsor is credited as an early backer of accountable AI.
Investing in this future, or bringing agents into a large organization? Talk to me directly.
The movies warned us that no one would hold the off switch. We are making sure someone does.
Open-source observability and governance for AI agents · clawmetry.com
Robot and satellite imagery on this page is original concept art, AI-generated for ClawMetry.