Enable AI. Keep it governed.
Give every team a safe path to agents, MCP servers, and skills, with approval, tool-call policy, and audit built in. Block a tool and it goes underground; approve it the right way and it stays visible.
The problem
Workarounds spread when the approved path is too slow.
Block a tool and someone pastes a long-lived token into a local config. Approve it and you have no idea what it reaches.
Uncover shadow usage
Every AI client on every device: Claude Code, Claude Desktop, ChatGPT, Cursor, Codex, Gemini CLI. Every MCP server, skill, and credential sitting in a local file, attributed to a person.
Approve MCPs and skills once
Publish to the catalog with scope and an approval gate. Installed on every client automatically, so the approved way is the easy way.
Govern the tool call
Allow what a team needs and filter the rest out of tools/list, so the model never sees it. Report-only first, then enforce per device or fleet-wide.
Track usage and audit
Every event attributed to a person, device, agent, tool, result, and tokens. Model caps by team. Ships to Splunk, Datadog, or any OpenTelemetry endpoint.
Shadow AI
See every AI client on every laptop.
The Lander reports what's running across the fleet, coding agents and chat apps alike, before you write a single policy.
- Coding and chat clients, MCP servers, and skills, attributed to a person
- Credentials found in local config files and env vars
- Combinations of tool calls and MCPs inside one session, where the real risk is
- Anything outside the catalog flagged, then stopped when you say so
Devices
42
AI clients
6
MCP servers
31
Unsanctioned
9
Tool-call policy
Say yes to the tool. Deny the one call that matters.
Approve GitHub for a team and github.delete_repo still gets denied, with the person, device, and rule on the record.
- Allow per team and per tool
- tools/list filtering, so disallowed tools never reach the model
- Report-only first, then enforce
github.delete_repo
repo: payments
- Rule
- allowed_tools
- Person
- j.doe@acme
- Device
- MBP-2291 verified
- Agent
- Claude Code
- Session
- 8f3a…
- Tokens
- 1,204 / 88
Recent
FAQ
Frequently asked questions
Get started
Start free. Grow into the fleet.
One developer, free and hosted, on a personal or business account. Teams and enterprises get the full platform and a team from us that works alongside yours to tailor policies, MCPs, and skills to your use case.
Personal
The Lander on your own machine, hosted by us. Inventory and native session telemetry for one developer. Sign up with a personal or a business account.
- 1 device, 1 user
- Inventory and session telemetry
- Personal or business account
Team & Enterprise
The Lander on every device plus the Connector, on our SaaS or in your cloud. We don't hand over a license and leave: we work embedded with your team to tailor policies, MCPs, and skills to your use case, and to bring your engineers up to speed.
- Every device, every user
- Our SaaS, your Kubernetes, or your MDM
- Embedded with your team, tailored to your use case