Claude Tag support
Govern Claude in Slack like every other client. The same identity, policy, and audit trail apply to every tool call it makes on a user's behalf.
Roadmap
The work in progress across the Speakeasy AI control plane, mirrored from our public roadmap. Quarters are what we are planning toward, not commitments. Vote on anything here and we read it.
12
In progress
Being built now, across every pillar.
7
Planned
Scoped and scheduled for a quarter.
11
Shipped
Live in the product, with release notes.
01 / Connect
MCP servers, SaaS connectors, and internal APIs provisioned through one catalog and reached through one gateway URL, with the clients your teams already run.
9 items
Govern Claude in Slack like every other client. The same identity, policy, and audit trail apply to every tool call it makes on a user's behalf.
Servers reach the right teams on day one. Role-based plugins land in the default project at onboarding, and anything outside a role's scope goes through an access request instead of a ticket.
Run the control plane on ai.speakeasy.com and on your own domain. The app becomes host-agnostic and app.getgram.ai is retired.
Stateless MCP advertised on every gateway endpoint, with legacy clients and proxy isolation preserved.
A Speakeasy-maintained catalog of MCP servers with verified publishers, tool manifests, and one-click distribution through the gateway. Replaces the third-party registry the catalog pulls from today.
Copilot runs on the control plane with the same identity, policy, and audit trail as Claude, Cursor, and Codex.
A first-party MCP server plus official skills for running the control plane from your agent: register, distribute, and diagnose MCP servers.
The gateway served on your tailnet, with the public path closed if you choose. Every request carries Tailscale user, device, and tag identity.
Connect private, on-prem MCP servers over an outbound-only tunnel, with no inbound ports, governed like every other server.
02 / Control
Who can use what, under which conditions. Scoped access by team, role, and tool, with the identity provider you already run as the source of truth.
7 items
Trust Speakeasy from your Okta tenant and assign applications to it using the permission structure Okta defines for XAA, so the control plane fits the admin model you already run.
Connect Okta, turn on SSO and directory sync, and import the applications your organization already assigns, in one guided flow.
Authorize downstream MCP connections through Okta identity chaining. A user signs in once and every connected service inherits that identity, with no per-service OAuth prompt.
Accept platform-issued JWTs from Kubernetes, GitHub Actions, SPIFFE, GCP, and AWS as an RFC 7523 grant on the token endpoint, so workloads reach MCP servers with no Speakeasy-issued secret.
A revocable static credential for agents that cannot complete an interactive OAuth flow, scoped to one gateway endpoint.
Cut one person's MCP clients off from your servers without deprovisioning them.
URL-based client identity and admission control for MCP OAuth. Only clients you have verified get a token.
03 / Secure
Prompts, responses, and tool calls inspected in flight. Policies that block, redact, or ask for review, with every verdict recorded.
6 items
Speakeasy as the AI security server for Claude Enterprise. Inline verdicts on Claude chat, Claude Code, and Claude Design before the model sees the prompt, reusing the risk policies and classifiers you already configure.
Redact sensitive fields from tool requests and responses in flight, by policy, so the original value never leaves the perimeter.
Warn-and-continue verdicts on the Inference Hooks path, alongside the block verdicts it supports today.
Flag likely false positives in risk findings for human review, and feed the decisions back into detection.
Enforce at the proxyEnforce policy where your model traffic already flows, with LiteLLM as the enforcement point.
A shadow MCP block opens a review with assembled evidence. Approve or deny with a scoped grant and a recorded rationale.
04 / Observe
Sessions, tokens, tool calls, and risk findings by team, client, and user, exported to the stack your security and finance teams already run.
8 items
A declarative query endpoint over sessions, tool calls, and every emitted metric, for the dashboards and reports you build yourself.
Extend shadow MCP detection to AI client use on managed devices: which clients run, where, and against which systems, with device agent coverage as the baseline.
Devices report the policy state actually applied, so coverage moves from a heartbeat to verified enforcement, with evidence you can hand to Drata or Vanta.
Trace one agent run across sub-agents, tools, and handoffs as a single lineage graph, from the first prompt to the last tool call.
Control plane data as automated evidence inside GRC platforms for ISO 42001, ISO 27001, and SOC 2.
Spending limits for teams and individuals, enforced at the control plane.
Start a task in one coding agent and finish it in another. The new agent opens the same repository with context from the previous session.
Agent sessions, MCP gateway traffic, and risk findings streamed as OpenTelemetry to any OTLP/HTTP destination you already run.