Watcher prevents AI agent incidents.

Our research is trusted by

OpenAIAnthropic
Google DeepMind
Meta
Microsoft

How Watcher Works

Watcher is the all-inclusive security layer for every coding agent your engineers use.

A diagram with the coding agents your engineers run in the centre: Claude Code, Codex and others. Three Watcher capabilities connect to that agent layer. Watcher deploys policy across the organization, blocks dangerous actions while agents work and reviews every session for incidents.

Secure policy rollout

100% of devices protected Deployed policy through MDM

Real-time blocking

blocked by Watcher terraform apply -auto-approve

Your coding agents

Claude Code
Codex
Others

Automated analysis

Recommended Action Update rule to prevent production bypass

Try Watcher Right Here

Explore how Watcher identified a coding agent that compromised a production environment.

The Watcher Analyzer showing a graded session in which an agent destroyed a production node group and an RDS replica.

Based on frontier AI security research

Apollo is the best place in the world for conducting scheming research. Extremely dedicated, hard working, collaborative. I’m glad OpenAI is working with them.
Wojciech Zaremba Co-founder, OpenAI
The joint OpenAI–Apollo investigations into model scheming are among the most consequential lines of research underway today. Apollo is an excellent place to do AGI safety work.
Jakub Pachocki Chief Scientist, OpenAI
Understanding deception and scheming in frontier models is essential for AI safety. Apollo Research’s work delivers insights the field urgently needs.
Yoshua Bengio Turing Award Laureate, most cited scientist in the world

AI agents threaten your organization

Every day you wait with implementing agent controls you risk expensive, irreversible incidents

  • No record of what your agents do
  • Nothing stops a destructive action
  • You only find out when it's too late
Book a call

FAQ

What coding agents work with Watcher?
Watcher works directly with Claude Code and Codex, and we're actively working on Cursor. If you want to use Watcher with another coding agent, let us know.
Is Watcher cloud-hosted or self-hosted?

By signing up and using Watcher here, it's cloud-hosted: monitors run on Apollo's managed monitoring platform (servers in Western Europe), so there's nothing to operate and no API key to bring.

For your organization, Watcher can be self-hosted — set up on your own infrastructure, entirely in your environment. Setup has historically taken around an hour. If you'd like to self-host, get in touch and we'll walk you through it.

How is this different from auto-mode?

Products like Claude Code's auto-mode and Codex's auto-review mode address the same core problem: reducing permission fatigue while maintaining safety. We think these are good products and are glad the labs are investing in safety by default. We work directly with these teams — see our red-teaming campaign with the Claude Code auto-mode team.

Watcher comes at the problem from an enterprise-ready angle:

  • Consistent rules across all coding agents. Watcher integrates across Claude Code and Codex. Your security policies are defined once and applied everywhere, rather than configured separately in each tool.
  • Organization-wide visibility. Auto-mode and auto-review are designed for a single developer using a single agent. Watcher gives teams centralized policy management, multi-session supervision, and Analyzer for reviewing failure patterns across all developers and sessions.
  • Cross-model monitoring. Built-in safety features use models from the same company as monitors. In practice, we've found that different models have different blind spots and biases. GPT models tend to be overly suspicious, Claude models can be too trusting of their own reasoning. Watcher lets you mix models across the pipeline (e.g., Gemini Flash for fast triage, Claude Sonnet for gateway) to get monitoring that doesn't share the agent's biases.
  • Admin-managed policy. Built-in modes are developer-controlled. Watcher supports locked settings, admin-distributed rules, and MDM deployment so that security teams can enforce policy, not just suggest it.
I have a different question
Feel free to book a call with us.

Want to get started today? Run it yourself

curl -fsSL https://github.com/ApolloResearch/watcher-bin/releases/latest/download/install.sh | bash -s -- --cloud
# Restart or open a new terminal
watcher