Prompt to production provenance.
Crash Override Endpoint is the developer-machine surface of the data plane. It observes AI-assisted development where it happens — on the engineer's own machine — so a single deterministic thread runs from a Claude Code planning session all the way through to the push to prod.
Zero-touch through your existing MDM · GA on macOS and Windows · observation mode today
Session timeline
Prompt to commit, in one thread
- E004 Prompt fix the payment retry logic
- E009 Plan 3 steps proposed · accepted
- E012 Read payments/retry.ts · 412 lines
- E018 Edit payments/retry.ts · +12 −4
- E024 Shell test suite · exit 0 · 124 passed
- E031 Commit signed · queued for build
We watch the agents. We are not one of them.
Endpoint runs on the developer's machine and observes AI-assisted engineering: which AI coding tools are used — Claude Code, Cursor, Copilot, Codex, Devin — what they were asked to do, what they produced, and how that work moves into the build and out to production. Everything it observes lands in the same provenance graph as Chalk's build and runtime data. Chalk is the data plane; Endpoint extends it to the machine.
Action-level audit
What the agent actually did
- A017 server.start issue-tracker
- A019 tool.call search_issues
- A023 tool.call read_file
- A026 tool.call write_file denied
- A031 reference spec/retry-policy
Three questions the AI era created.
You committed real budget to AI coding tools and real political capital to the "use AI" mandate. These are the questions you are now accountable for — and they only become answerable once observability reaches the developer machine.
Am I realizing a return on our AI spend?
Endpoint ties token and tool spend to delivered outcomes — merges, deploys, tasks actually closed — not to activity. Token-to-ROI, measured rather than asserted.
How well are my engineers actually using AI?
Endpoint measures AI's effect on delivery flow — AI-era DORA metrics — so managers can see where AI is accelerating work and where it is spinning.
Does the intent set at planning survive to production?
Endpoint follows one deterministic thread from the planning session through generated code, build, deploy and runtime — so a plan can be checked against what actually shipped.
Return on token spend
Token spend, one team, one sprint
- 62% shipped
- 23% in review
- 15% abandoned
- 38 merges
- 12 deploys
- 51 tasks closed
Action-level detail, not a summary.
Observed on the machine, deterministically. No model sits in the data path guessing about your code.
- Sessions
- For transcript-backed tools such as Claude Code and Codex: the prompts and responses themselves, tied to the user, the files, the tools and the network activity around them.
- Actions
- Tool calls, denied tool use, shell execution with exit codes, and file create, modify and delete.
- MCP
- First-class visibility into Model Context Protocol activity: server starts, tool calls and references.
- Network
- External calls the agent initiates — DNS, URLs, methods, status codes and provider routes.
- Attribution
- Agent-to-source and engineer-to-source attribution, with provider, model and session identity.
- Timeline
- A session-level unified timeline joining AI activity to source change, build, deploy and runtime.
Every developer covered, without anyone opting in.
Endpoint ships zero-touch through the MDM you already run. There is no developer opt-in, no IDE plugin, no Dockerfile change and no CI configuration — so coverage does not depend on every team remembering to instrument every repo.
Zero-touch rollout
Deployed through your existing MDM. No developer opt-in required.
Generally available
macOS and Windows today. Linux is coming soon.
Observation mode
Endpoint observes today. Policy enforcement arrives as an opt-in in Q3 2026.
They watch the prompt. We follow it to prod.
The market is filling with AI security and DLP tooling that sits at the prompt or the network egress and tries to control: block prompts, redact, gate. There are two problems with that. Control-first is the antipattern engineers route around — you cannot govern what you cannot see, and gatekeeping kills adoption. More fundamentally, those tools can tell you a prompt happened, but not whether that prompt turned into shipped value, or whether the engineer's intent survived to production. They measure risk at the doorway. We measure delivery through the whole house.
Visibility and guardrails, not a checkpoint.
Endpoint answers security's requirements from the same observed data — without becoming the gate engineers route around.
Shadow AI discovery
Find unsanctioned AI coding tools in use across the fleet.
Attribution
Agent-to-source and engineer-to-source, surviving rebases and squashes.
Action-level audit
What the tool did: files, shell, network and MCP calls.
Audit evidence
Assembled as a byproduct of observation, not reconstructed later.
What engineering leaders ask first.
No, and the distinction matters to us. Endpoint records what AI coding tools did — prompts, tool calls, file changes, commits — not what the human typed outside that context. It captures no keystrokes or screen content outside the coding context. Developers experience it as attribution and credit: their AI-assisted work is traceable, and when something breaks the build and production picture is already assembled.
View full page →No. It is a lightweight background process with no IDE plugins to install, no workflow changes and no approval gates. It runs in observation mode today; policy enforcement arrives as an opt-in in Q3 2026.
View full page →Those tools sit at the prompt or the egress and try to control. Endpoint measures and traces. They can tell you a prompt happened; they cannot tell you whether it turned into shipped value or whether intent survived to production. They watch the prompt. We follow it to prod.
View full page →They are two halves of one thread. Chalk carries provenance from the build through to runtime; Endpoint extends that same thread left, to the machine where the code is now written. Endpoint is a surface on the platform, not a standalone tool.
View full page →Endpoint is generally available on macOS and Windows today. Linux is coming soon.
View full page →See the thread from prompt to production.
Book 30 minutes with an engineer. We will show you a real session traced from an AI planning prompt through the build and into a running container.