HawkeyeOne place to run and oversee AI work
Get started
Run and oversee AI work everywhere

Coordinate every AI client, tool, and computer from one trusted place.

Hawkeye connects the AI tools you already use across enrolled computers. Give each task only the access it needs, inspect connected work and its privileged-action record, and bring in a person when the workflow exposes a real decision or handoff.

Single-use enrollment linksApproved client pairings Protected values stay out of promptsPrivileged actions are attributable
Product overview · The workflow at right is illustrative, not customer activity · Sign in for authoritative organization data
Works acrossAI clientsConnected tools (MCP + APIs) BrowsersTerminalsEnrolled computersPeople on any device
Hawkeye in one minute

You say what needs to happen. Hawkeye organizes the approved work and keeps you in control.

1

Describe the result

Ask in everyday language. You do not have to choose every tool or computer before you begin.

2

Hawkeye coordinates the work

It brings together approved AI clients, connected tools, project context, browsers, and enrolled computers.

3

You stay informed and in charge

Inspect progress and authority, answer genuine requests, and step in where human judgment is required.

New to AI agents? An agent is an AI worker with a job and rules. A session is one running copy of that worker or tool. Hawkeye keeps their identity and authority explicit.

Start with the outcome

Choose an example and follow it from request to attributable result.

These scenarios explain the production interaction model. They do not execute work or represent connected customer systems.

Choose an example workflow
Safe release coordination

Coordinate the build, policy review, and partner brief without losing the approval boundary.

“Ship a release, verify the risk, and brief the partner team.”

The workflow can span tools and computers while tenant boundaries and human ownership stay explicit.

Open Hawkeye
  1. An enrolled computer runs the approved build work

  2. Connected AI clients prepare the review and brief

  3. Cross-organization sharing remains a request the other side may refuse

  4. The audit record keeps the request, authority, actions, and result together

Only the approved information

Give an AI the useful project context without turning the whole organization into its context window.

“Synthesize this research using only the approved project sources.”

Useful context stays bounded by organization, project, subject, purpose, and time instead of being copied broadly.

Read the access model
  1. The AI client identifies itself through an approved pairing

  2. The task uses the project information and permissions it was granted

  3. Protected credential values do not pass through the model

  4. Access and resulting privileged actions remain attributable

Safe human handoff

Bring in a person for a blocked browser step without implying unrestricted control of the computer.

“Finish the provider sign-in that requires a person, then return control.”

Browser handoff is a bounded, consented workflow; unrelated content is not presented as part of the grant.

Review the trust model
  1. The task reports the blocker instead of inventing a success state

  2. The person reviews the requested browser scope and purpose

  3. The automation pauses while the limited handoff is active

  4. The handback and resumed work are recorded

Power you can click into

Let AI do more without losing visibility or control.

Every card leads to a real public route or sign-in boundary. No usage totals, customer logos, certifications, or simulated success states are presented as evidence.

Coordinate one result across everything

Turn one request into work across approved AI clients, connected tools, browsers, files, and enrolled computers.

Start with the tools you already use Connect your AI

Scale without hiding the trail

Inspect connected machines, sessions, requests, and recorded privileged actions without presenting illustrative activity as live data.

Live organization data appears only after sign-in Open your workspace

Use the right surface for the job

Work from the web and desktop today, with every published download and mobile availability stated at its verified level.

Platform-specific availability and signatures See downloads

Use protected access without exposing values

Keep credentials out of prompts and grant only the project, resource, subject, purpose, and time the work needs.

Concrete pairing, scope, and revocation facts Review security

Keep people in the right loop

Route genuine approval and decision requests through configured channels while keeping duplicate responses from becoming duplicate actions.

Notification channels stay optional See how requests work

Stay connected to every enrolled computer

Reach shell, desktop, browser, and file tools through the machine's own outbound connection—nothing on the internet dials in to it.

Single-use enrollment links and outbound tunnels Add a computer

Send the right thing to the right place

Move approved files and instructions across connected machines and organizations with explicit authority and an attributable record.

Cross-organization work remains a request Read the documentation
Why Hawkeye

Make your AI work feel like one governed system.

Without Hawkeye

More automation creates more places to lose context, authority, and accountability.

  • AI clients, tools, browsers, and computers stay fragmented
  • It is hard to tell which runtime acted or under whose authority
  • Requests scatter across channels and invite duplicate action
  • Project context and credentials are copied too broadly
  • Logs show isolated events instead of the path from request to result
With Hawkeye

Identity, access, human decisions, and privileged actions stay connected.

  • One outcome can coordinate approved clients, tools, and computers
  • Sessions identify the runtime, purpose, and recent heartbeat
  • Genuine requests preserve version and first-valid-response semantics
  • Work receives bounded project and protected-resource access
  • Audit records keep authority and privileged actions attributable
Built around clear boundaries

Connected where it is verified. Explicit at every boundary.

Hawkeye is built for teams that want AI clients to do useful work while keeping tenant boundaries, access, revocation, and attribution concrete.

Explore the trust model
Approved pairingClients receive scoped credentials through a review flow, not a Hawkeye password. Session identityRegistered runtime sessions can attest, identify their work, and report heartbeats. Temporary, specific accessAuthority can be bounded by organization, project, subject, purpose, and expiry. Human response semanticsVersioned requests accept one valid response and retire duplicate controls.
Straight answers

Questions teams ask first.

Does Hawkeye replace Claude, ChatGPT, Codex, MCP, or my existing agents?

No. Hawkeye connects the AI clients and tools you already use, gives them approved paths to your computers, and keeps identity, authority, requests, and privileged actions inspectable.

Do I have to expose an inbound port on every computer?

Not to the internet. Enrolled computers dial out to Hawkeye, the panel reaches them only back down that tunnel, and nothing needs port-forwarding or a firewall hole. Being exact: on the machine itself the agent does listen on port 8891 as a faster path for callers already on your own LAN or tailnet. It takes the same key as every other path, it is not internet-reachable, and XFER_PORT_DIRECT=0 turns it off. Enrollment links are single-use and expiring, and clients pair through an approval flow instead of receiving your Hawkeye password.

Can an AI client read raw passwords or API keys?

Credentials do not pass through the model. Hawkeye's protected-access model is designed around permission to use an approved credential for a bounded purpose, not copying its raw value into a prompt or request.

What happens when automation needs a person?

A real request can be routed to the channels you configured and the work can wait for a valid response. Per-action policy enforcement is not live yet, so this page does not claim every privileged action pauses for approval.

Is the activity picture above showing customer data?

No. It is an illustrative workflow with no counters or production identifiers. Sign in to see authoritative data for your organization. Correlated Live map, cloud Computer provisioning, and generally published native phone apps are not presented here as available today.

Production details and current boundaries

The polished overview above does not replace the facts below.

Setup, platform availability, notification configuration, enrollment, policy enforcement, downloads, pricing, and legal routes remain stated at their current verified level.

Think of it as one control room for every computer you own. Instead of remoting into each machine by hand, you tell your AI what you want — on any machine, or across all of them — and it does it. Machine enrolment and client pairing require approval; action policy currently evaluates and logs what it would block rather than enforcing per-action approval.

You ask, it acts

Plain requests in chat — "free up disk on the machine that's full," "run the tests on the Linux machine." It works out which machine and does it.

You stay in control

Nothing joins without a link you minted, and no client pairs without you approving the device. Sensitive actions ask first, and everything is written to an audit trail.

Every machine, one place

Windows, Mac, Linux and your phone — shell, desktop control, browsers and file transfer, from one app or your existing AI client.

Get going

Get going in three steps.

No keys to paste. The app signs you in, and each machine joins with a one-time link you mint.

Install the app

Download Hawkeye for your computer. It signs in as you, runs quietly in the tray, and keeps that machine reachable.

Windows · macOS · Linux

Add your machines

Mint a one-time link and run it on each computer. Nothing is added to your org without that link, and a machine that can't prove what it is waits for you on Machines.

one link per machine · single-use

Point your AI at them

Connect Claude, ChatGPT/Codex, or use Hawkeye's own chat. Approve the pairing once, then just ask.

connect Claude, Codex, or just chat

What you can actually ask it

Real things people run on day one.

One machine, or all of them at once — in your own words, not a command syntax to learn.

"Which machine is low on disk? Free 20 GB of caches on it.""Run the test suite on the Linux machine and tell me what fails.""Open my work Mac's desktop so I can grab a file.""Copy build-artifact.zip from the build server to my laptop.""Check every machine for pending OS updates.""Restart the dev server on the staging machine when the build lands."

Everything it can reach

What 81 tools actually means.

Six capabilities, once a machine is paired — each one is a tool your AI gets to use, not a control panel you have to learn.

Shell

Run a command on any enrolled machine — watched live, or fire-and-forget in the background.

Desktop control

See the real screen and drive it — click, type, grab a file, or fix something by hand.

Browsers

A real, driveable browser on the machine: navigate, read pages, fill forms, screenshot.

File transfer

Move a file between your machines directly — no email attachment, no USB stick.

Agent channel

Your agents on different machines talk to each other — hand off work, ask for a file, coordinate.

Cross-org asks

On Team and Enterprise, another org's agent can ask yours for something — and you can refuse it.

How it thinks

One agent. Your own tools first. A cloud worker only if you need one.

Three panels, in the order a stranger actually needs them — talk to it, see what runs it, know what happens with nothing installed yet.

1. Talk to one agent

Home is the one conversation — your machines, your live sessions and anything waiting for your approval sit around it. Sign in to see your own fleet; Home does not ask you to paste another API key.

2. It starts sessions on your machines

Install the app and it runs Claude Code, Codex or Grok exactly as you already have them installed and signed in. You keep the Max, ChatGPT and SuperGrok logins in those apps — Hawkeye starts the session, it never touches or reuses the credential behind it.

3. No machine? Paste a key

Paste an OpenRouter, Anthropic, OpenAI or xAI API key during first-run and we stand up a cloud Computer for you instead of an installer. You will approve the spend and dangerous actions before the planned cloud Computer runs. (Provisioning is designed, not live yet. Today this step records what you'd want and tells you honestly it's on the way.)

Get a computer

Install it, sign in, and your machine shows up by itself.

The desktop app pairs with your account — you approve it in the browser, it keeps the daemon running quietly, and it sits in your system tray. No key to copy, no terminal to keep open.

Windows

Hawkeye-Setup-0.1.31.exe — 207 MB installer.
Code-signed (Azure Trusted Signing). A fresh publisher can still see a brief SmartScreen notice while download reputation builds -- if so, choose More info → Run anyway. Check the hash first if you would rather not take our word for it.

Linux

Hawkeye-0.1.31.AppImage (255 MB) or .deb (208 MB).
Unsigned — Linux has no equivalent gate. AppImage: chmod +x then run it — needs libfuse2, which Ubuntu 22.04+ does not install by default (sudo apt install libfuse2, or run with --appimage-extract and launch squashfs-root/AppRun if you would rather not install anything). .deb: sudo apt install ./hawkeye-desktop_0.1.31_amd64.deb resolves its dependencies for you — plain dpkg -i will leave it unconfigured.

macOS

Apple Silicon .dmg (253 MB) · Intel .dmg (257 MB).
Code-signed and notarized (Developer ID). Opens with a plain double-click; no right-click workaround needed. Apple Silicon: also install the permission-service .pkg (336 MB) afterward so Screen Recording/Accessibility Request buttons in the app actually work — it does not install the app itself, only the native permission service the app above needs.

Phone

The native iOS and Android apps are in active development and not yet published for general download. This page will not claim otherwise. Until then, sign in to this site from your phone's browser; your machines, your agent and your approvals all work there too.

Verify what you downloaded: SHA256SUMS.txt, or check the signature yourself — signtool verify /pa /v on Windows, spctl -a -vvv -t open on macOS.

How it works

From nothing to a governed fleet in four steps.

Enrolment is deliberate at every step: the link is minted by a person, for one machine, and a machine that cannot prove what it is waits for a human before it joins.

Create an org

Your org is a hard tenant boundary. The machines, tokens and policies inside it are yours; a resource in someone else's org is a request they get to refuse, never a command you can issue.

Install with one command

Mint a single-use, expiring install token and run it on the machine. The agent dials out to Hawkeye — nothing on the internet dials in, and no router or firewall has to be opened for it.

A human authorises the join, and every action is recorded

An authenticated admin mints the link — single-use, expiring, for one machine — and approves which AI client gets paired, with the scopes it asked for shown before you agree. A machine that enrols on that link and attests strongly joins on the link's authority; one that cannot attest waits for a person on Machines. Per-action approval is not enforced yet — the policy is evaluated and logged, not applied. We would rather say that here than let you find out later.

Get notified how you choose

In-app, email or Slack — every channel optional and off until you turn it on. You decide which events are worth a ping and where it lands.

Adding a machine — where to start

$ curl -fsSL https://app.gethawkeye.app/install | sh

This tells you how to get YOUR install link; it does not enrol anything on its own. Every link belongs to one org, is single-use and expires — so a machine can never be added by a command someone copied off a website.

Built so you stay in charge

Hawkeye is powerful on purpose, so the guardrails are the product.

The same discipline at every boundary the product actually holds: who joins, which client is paired, which org may ask, and how wide a grant goes. Enrollment and client pairing require approval; individual actions after pairing do not.

Multi-tenant orgs, hard boundaries

Each org is its own tenant. A machine in another org is not a filter you can widen to reach — it is not addressable at all. Crossing the boundary is a request the other side must grant, never a command.

One-command install, single-use tokens

Enrol a machine with one line. Every join token is single-use, time-limited and revocable on its own, so a leaked token costs you one token, not the fleet.

Notifications your way

In-app, email or Slack. Every channel is optional and off by default — route what matters to wherever you actually are.

Every action audited and attributable

Who asked, what ran, when, on which machine, under whose authority — recorded for every privileged action. Approving an enrolment from a Slack card and from the panel share one code path and one trail. The record is what you get today; a gate in front of each action is not built yet.

Remote control with nothing open to the internet

Your machines dial out to Hawkeye; Hawkeye never dials in. The panel reaches a machine only back down that machine's own outbound tunnel — nothing to port-forward, nothing on the public internet to scan. The agent does keep one listener of its own, on 8891, as a faster path for callers already on your LAN or tailnet: same bearer key, on by default, and gone with XFER_PORT_DIRECT=0.

Built for audit

Designed to be reviewed, not just trusted.

Every output is traceable to what ran, when, which version, on whose authority, with what inputs. Sessions are server-side, credentials never pass through the model, and a human stands at every boundary — what joins the org, what gets paired, which org may ask. When someone asks "who let the AI do that?", the answer is a row, not a shrug.

Authority boundary today (observe_only). Enrollment and client pairing require approval. After pairing, allowed actions execute without per-action approval: each machine's policy is evaluated and written to the audit trail in observe mode (XFER_POLICY_MODE defaults to observe, deliberately) rather than applied. A connected AI client can still raise an explicit human request when it creates one, and cross-org access is still a request the other side grants. What that gives you between those boundaries is a record of what was done, not a gate in front of it. Read it as evidence after the fact, not as a control that stops something first. One caller stands outside even the record's attribution: the shared fleet key is a break-glass credential, accepted without an identity chain, so its actions are attributable to the key rather than to a person, and the policy that is being observed is not evaluated for it at all. Its uses are counted and the recent ones kept, which is how a machine can show you how often break-glass was reached for. Narrowing it is open work, not a shipped property — treat possession of that key as possession of the fleet.

Pricing

Free during the beta. Paid plans priced plainly when they ship.

Hawkeye is invite-only right now and free to use — no card, real limits (5 machines and 3 people per org on Free today, and both are refused at the line, not merely counted), not a timed trial. Team and Enterprise pricing isn't finalized yet; when it is, it will be one flat monthly price per org, not per seat, stated on the pricing page the same way the limits above are — read off the plan the product enforces, not guessed.

Ready to connect the system?

Let AI do more while identity, access, and human ownership stay explicit.

Create or request an account, connect an AI client you already use, and add the first computer with a single-use enrollment link.

Get started See verified downloads
Current-boundary note: per-action policy is evaluated and logged rather than enforced. Cloud Computer provisioning and generally published native phone apps are not live. The workflow illustration above contains no customer data or simulated counters.