What is Watcher?
Watcher is a runtime security layer for AI coding agents, built by the safety lab Apollo Research. It checks each agent action before it runs, blocks moves that cross your risk threshold, and reviews past sessions for incidents. Security teams set one policy centrally and push it to every developer device.
Top Features:
- Real-time blocking: stops agent commands that break policy before they ever run.
- Central policies: define rules once and push them to devices through MDM.
- Session analysis: reviews agent sessions, flags incidents, and suggests rule updates.
Use Cases:
- Production safety: stop agents from running destructive commands on live infrastructure.
- Leak prevention: catch agents sending secrets or code to unapproved places.
- Incident review: investigate what an agent did and why it was flagged.
Who Can Use Watcher?
- Security teams: govern how developers use Claude Code, Codex, and similar agents.
- Engineering leaders: let teams adopt coding agents without losing sight of actions.
- Regulated firms: self-host monitoring inside your own infrastructure for tighter control.
Pricing
- Self-serve (free): install with one command and monitor Claude Code or Codex.
- Enterprise (contact sales): 50+ agent harnesses and gateways, plus self-hosted deployment options.
- Discovery call (free): a 30 minute session to review your agents and policies.
Pros and Cons
Pros:
- Research backing: built by a lab known for frontier model safety evaluations.
- Few false alarms: under one percent false positives on benign tool calls.
- Flexible hosting: use the managed platform in Western Europe or self-host.
Cons:
- Limited self-serve: the free version connects only to Claude Code and Codex.
- Added overhead: checks add about six to eight percent latency and some cost.
- Hidden pricing: enterprise costs are not published and need a sales call.
FAQs:
1) Which agents does it support?
The free version covers Claude Code and Codex, and enterprise supports 50+ harnesses.
2) Can it block actions before they run?
Yes, it checks each tool call and blocks those above your risk threshold.
3) Is it cloud hosted or self-hosted?
Both, with a managed platform in Western Europe or your own infrastructure.
4) Does it slow agents down?
Apollo estimates six to eight percent added latency and three to five percent cost.
5) Who builds this tool?
Apollo Research, a public benefit company focused on AI safety and scheming research.