What Token Observe is, answered in full.
- Questions in this subject
- 8
- Questions across the whole set
- 49
- Subject, in the reading order
- 1/7
Each answer stands on its own
Every answer here is written to be read without its question, without the paragraph before it and without the rest of the site, because the form it will most often be read in is somebody else's summary. Where there is a limit, it is in the same sentence as the claim rather than in a note underneath it.
What is Token Observe?
Token Observe is a customer-hosted platform for SMBs and mid-market businesses that answers four questions about the AI your organisation uses: what it costs, what it is being asked to do, which tools nobody approved, and who may use any of it. It keeps a register of your AI services and subscriptions, each with a named owner. It imports invoices as JSON or CSV to record what was actually billed in each currency, and records metered token estimates separately — a charge and an estimate are different measurements, and adding them together produces a total that is true of nothing. It classifies what it observes as approved, prohibited, unknown or unobserved, so an approved paid subscription is never reported as unauthorised use and a source nobody has connected is reported as unknown rather than as zero usage. Where a configured integration exposes the content, it records bounded, redacted prompts, replies and tool activity with truncation and source provenance kept beside them; hidden chain of thought is not readable from any provider and is not claimed. Operators reach all of it through one dashboard, REST API and MCP interface under team scoping. It runs on your own infrastructure behind your own firewall, model requests go to your own provider accounts on your own keys, and the vendor receives no prompts, keys, telemetry or trace data. The inline governance capabilities — permissions, budgets, redaction, approvals and a hash-chained audit log — still ship and are described across the platform pages; since the product direction was updated on 6 September 2026 they are retained capabilities rather than the headline.
What is Token Observe not?
Token Observe is not a FinOps suite for your whole cloud bill: it covers AI services, subscriptions and model traffic, and nothing else. It does not discover every subscription by itself — an invoice import finds what the invoice lists — and it does not read hidden chain of thought, because no provider exposes it. It is not an LLM evaluation platform, not an identity provider, not a sandbox or durable agent runtime, not a CMDB-style AI inventory, not a general AI firewall or prompt scanner, not a static agent-BOM scanner, and not an agent marketplace. Those are named strategic non-goals in Token Observe’s own roadmap, and the instruction that follows them is to build adapters and evidence exchange for those layers instead — so the recorded strategy is to federate your identity system, consume your security platform’s verdicts, and run above or beside your existing gateway rather than ask you to remove any of them. It does ship a registry, provider routing, quotas, cost dashboards, prompt and response redaction, trace trees and MCP tool ACLs. Every one of those is treated as table stakes rather than as a reason to buy, because most of the market now ships them too.
How does Token Observe work out what our AI actually costs?
Two separate measurements, kept separate on purpose. The first is what you were actually billed: you register each AI service and subscription with a named owner, then import the invoices as JSON or CSV. Charges are recorded per currency and carry their source and the period they cover, and repeated imports are replay-protected so loading the same invoice twice does not double the total. The second is metered usage through the gateway, priced as a token-cost estimate. Those two numbers are never added together, because an invoice and an estimate measure different things and a combined figure would be true of nothing — a subscription you are billed for monthly and the API traffic beside it are not the same money, and presenting them as one number is the fastest way to produce a total nobody can reconcile against a real vendor record. Two limits matter before you plan around it. An import finds what the invoice lists, so it does not by itself discover a subscription nobody has told you about or expensed elsewhere. And live billing adapters that reconcile continuously against real vendor records are not built yet — what ships today is the register, the import path and the provenance on both sides of it.
Is Token Observe the same product as AgentControl Plane?
Yes. AgentControl Plane is the engineering name Token Observe is developed under: it is the name on the repository, the licence, the architecture decision records and the threat model, so anyone who has read the source will search for it. Token Observe is the product name and is the only name used everywhere else, because two names in the copy split one entity into two half-described ones. Nothing else differs — same code, same source-available licence, same self-hosted deployment, same published defect list. If you arrived from the repository, the documents you have already read remain the authority: the data-flow document, the threat model, the compliance mappings and the known-issues list are what a security review should actually run on, and this site paraphrases them rather than replacing them. Where the two disagree, the repository is right and the site is a defect.
What does agent action assurance mean, and is it still what Token Observe leads with?
Agent action assurance means proving that a specific delegated authority, and the business effect that followed from using it, both stayed legitimate. The trigger is a consequential, externally observable action — a refund, a deployment, an email, a ticket transition, a database write — where the API returning 200 is not acceptable evidence that the thing happened, or happened only once. Effect contracts, payload-bound approvals and an anchorable audit chain are what answer it, and all three still ship; the platform pages describe each one. It is no longer what the product leads with. The product direction was updated on 6 September 2026 to a customer-hosted platform for seeing AI spend and observable AI activity, identifying unauthorised tools and governing access, aimed at SMBs and mid-market businesses, and the roadmap that records that change says in terms that it supersedes the earlier action-assurance-led direction and that these capabilities are retained rather than the default source of new scope. If action assurance is the reason you are here, nothing has been removed and the capability pages are the place to start. If you arrived about an AI bill nobody can explain, that is now the front door.
Who is Token Observe for?
Token Observe’s buyer is a platform team that owns a handful of agents and has been asked who approved that. The documented pilot shape for Token Observe is one self-hosted deployment inside the customer’s own network, roughly five to fifty API-key agents owned by one platform team, a small named console population signing in through the customer’s identity provider, one or two model providers and a bounded set of pinned MCP tools. Four other people read the same evidence and ask different questions: a CISO about fail-closed enforcement, key custody and blast radius; a data protection officer about retention, erasure and whether redaction is sufficient; counsel about the licence and the data-processing position; and an operations owner about backup, restore and what happens when a fail-closed gateway is unavailable. Each of those has an answer here, including the several places where the answer is no.
What does Token Observe include?
Token Observe ships twelve capabilities, and the order they are listed in matters because half of them are table stakes in this market. The differentiated ones first: effect contracts, which extend an allow or deny decision into preconditions, reserve, execute, verify postconditions, then commit or compensate, so an action cannot be reported complete solely because an API returned success, though that is a bounded slice whose real downstream drill remains an open gate; human approvals bound to one exact payload, single-use and expiring; a policy engine with shadow mode and backtesting before enforcement; an audit chain whose keyed epochs and off-box Ed25519 anchoring are both optional and inert until you configure a key for each; agent permissions that deny by default and intersect across every delegation hop; and a shadow-AI radar that reconciles bills, egress, service-account keys, IDE telemetry and its own caller and price consistency checks against the agents you govern. Then the ones the market also has: the agent registry, model routing, spend controls, the flight recorder, an MCP gateway, and endpoint seats — which is preview, not a production endpoint-control claim.
What stage is Token Observe at, and can it run production-critical workloads?
Token Observe is pre-general-availability and cannot be recommended for production-critical workloads, and its repository says so before anyone selling it does. The current decision record makes broad, production-critical general availability a no-go, and states that even a design-partner launch is not authorised by the repository alone until ten gates pass: counsel approval of the licence, independent security testing with critical and high findings closed, an immutable semver release with SBOM and provenance, technical readiness returning no blockers in the partner’s own environment, a written pilot scope, capacity and recovery measured on partner-shaped data, the partner’s real integrations exercised against live accounts, agreed success criteria, named operations roles, and residual risks accepted in writing. What can be offered once they pass is a tightly scoped, non-production-critical design-partner evaluation; the current record authorises no launch, paid or otherwise. That is a worse sentence than most vendors write and a more useful one, because the alternative is discovering the same list halfway through your own security review.
If the answer above is close but not quite the case you have, the specific version of it is a better question than the general one, and it gets a specific reply.
Ask the specific version49 questions, in 7 subjects
How it works
The request path step by step: how an agent is onboarded, what happens inline, what streaming and failover do, and what happens when something is unavailable.
7 questionsSecurity and threat model
The threat model, key custody, injection and redaction limits, whether the audit log can be rewritten, vulnerability disclosure, and what has not been tested.
10 questionsCompliance and evidence
EU AI Act, ISO/IEC 42001, NIST AI RMF and OWASP mappings, what an evidence export proves, retention and erasure — and which certifications do not exist.
6 questionsDeployment and operations
What it runs on, how long onboarding takes, backup and restore, upgrades and rollback, air-gapped installs, and why there is no high-availability topology.
7 questionsLicence, pricing and support
The source-available licence, how the product is metered, the thirty-day evaluation, the support model, and what procurement has to accept in writing.
6 questionsAlternatives and adjacent tools
Where Token Observe sits against gateways, observability, security platforms and identity products — and the case for and against building it yourself.
5 questionsBring the question this page did not answer.
Write to hello@tenhaw.com with what your agents do, which providers they call and what would have to be true for you to put something in front of them. James Rooney replies. You will get a straight answer about whether Token Observe fits, including when it does not.
no form · no qualification step · no sales desk · the other three ways in