Backplanes Spotlight
Spotlight by Backplanes reads your Claude Code and Codex agent sessions to generate reports showing what each agent actually did, flagging security issues, credential access, and external services.
At a Glance
About Backplanes Spotlight
Spotlight by Backplanes is a CLI tool that automatically captures and analyzes AI agent sessions — specifically Claude Code and Codex — and generates structured reports after each session ends. It is free for individual developers and teams, with no seat counts or trial timers. The team behind it includes leaders and practitioners from Google, Twilio, ngrok, and Algolia, and the company is backed by Slow Ventures, Bloomberg Beta, HF0, Spacecadet Ventures, Theory Forge, and Fenwick.
What It Is
Spotlight is an agent observability tool that sits on a developer's local machine and watches AI coding agent sessions. When a session ends, it produces a session report covering what the agent did, what files it touched, what external services it contacted, and whether anything warrants review. The core problem it addresses is that agentic coding sessions — which can run for 30–60 minutes unattended — are largely invisible to the developer who kicked them off.
How the Session Report Works
Each Spotlight report is structured around a verdict ("Needs review" or "Business as usual"), a time breakdown, and a set of findings. The homepage example shows a report flagging that /etc/passwd was opened during a password-reset task, listing three approaches the agent tried, noting that tokens expire in 15 minutes, and surfacing a new external domain (api.resend.com). Reports also count files touched, commands run, and external services reached.
Local Redaction and Privacy Architecture
Spotlight performs local redaction of PII and credentials before any data leaves the developer's machine. The CLI reads sessions only after they end — it does not require OAuth into Anthropic or OpenAI, and it does not intercept live traffic. This design keeps the developer in flow while still capturing the full session artifact for analysis.
Setup Path
Installation is a single curl command that works on macOS, Linux, and WSL 2. After running the installer, it authenticates in the browser, creates a team account, and begins capturing sessions automatically as they finish. The first report appears after the next completed session.
Audience and Org Rollout
Backplanes segments its audience into four groups: engineers and builders (faster review of their own sessions), engineering managers (where the team is spending AI capacity), CFOs (spend, ROI, and capacity by team and tool), and CISOs (external access, data egress, and policy). The homepage notes that org-wide rollouts with attribution, volume, or specific controls require a direct conversation with the team.
Current Status and Roadmap
As of the current homepage, Spotlight supports Claude Code and Codex. The roadmap section invites users to vote on future platform support, listing Cursor, open-source CLIs, Google, and others as candidates. The company describes Spotlight as "move one," signaling that broader agent visibility across teams and organizations is the longer-term product direction.
Community Discussions
Be the first to start a conversation about Backplanes Spotlight
Share your experience with Backplanes Spotlight, ask questions, or help others learn from your insights.
Pricing
Free
Free for individual developers and teams with no seat counts or trial clock.
- Session reports for Claude Code and Codex
- Local PII and credential redaction
- External domain and service tracking
- Automatic session capture
- No seat limits
Enterprise
Org-wide rollout with attribution, volume, and specific controls. Contact sales for pricing.
- Org-level reports
- Attribution and volume controls
- Security, Engineering, and Spend views
- Custom controls and policy management
Capabilities
Key Features
- Automatic session capture after agent sessions end
- Session reports with verdict, time breakdown, and findings
- Local PII and credential redaction before data leaves device
- Flags credential access and file system anomalies
- Tracks external domains and services contacted by agents
- Org-level reports with Security, Engineering, and Spend views
- MCP and external access tracking
- No OAuth into Anthropic or OpenAI required
- Works with Claude Code and Codex
- CLI-based installation with browser authentication
