Always available
The operating diagram stays live independent of any one engineer's laptop.
Run one daemon inside your network. It keeps your Git-tracked operating map current and serves the same context to every authorized browser, internal tool, and read-only agent.
One topology · Unlimited teammates · One trusted network vantage point · Credentials stay on one host
This is the hand-authored diagram we use to understand reticle.live, connected to current health evidence from the Team Daemon it describes. The public browser is read-only.
Pan, inspect, and export the diagram. Read-only access is enforced by the daemon. Open full screen ↗
Desktop and Team use the same intentionally defined model. Team keeps collection running and makes one current view available across the organization.
The operating diagram stays live independent of any one engineer's laptop.
Teammates inspect the same topology, evidence, notes, and timestamps from a browser.
Checks run from one managed host. Viewers and read-only integrations get context without receiving SSH credentials or shell access.
Keep dependencies, current evidence, notes, and freshness in one shared browser view.
New operators and escalation paths can inspect the architecture without waiting for its original author.
Persist bounded actions with approvals, timeouts, and optional fresh-signal preconditions.
| Capability | Desktop | Team Daemon |
|---|---|---|
| Deployment | Standalone, local-only app | Always-on daemon on your infrastructure |
| Access | One local operator | Unlimited browser seats |
| Identity | Local OS user | Shared editor/viewer bearer tokens; SSO is not included |
| Topology scope | Multiple local workspaces | One topology per licensed daemon |
| UI and integrations | Local UI; loopback JSON API; read-only MCP | Browser UI; authenticated JSON API; read-only MCP |
| Checks | Fixed checks; optional privileged commands | Fixed checks; gated custom commands |
| Shell | Local privileged shell available | No Team shell |
| Audit logs | Not a shared service | JSONL when --audit-log is configured |
| License | Free, MIT | Commercial subscription |
Starting at $3,000 one-time, we deploy the Team Daemon, establish TLS and access controls, and map the agreed architecture from your existing diagrams, runbooks, and operator knowledge.
Install the daemon on a trusted host inside your network and configure TLS.
Set viewer and editor access, least-privilege OS permissions, and restricted SSH principals.
Build the first agreed operating diagram and connect its initial health checks.
Fixed HTTP and read-only SSH checks remain the default. Custom remote SSH or local Bash checks run only when the operator enables them.
Start the daemon with --allow-custom-commands.
Editors manage definitions. New checks are enabled and viewer-visible by default; named actions require approval by default. Direct YAML writers are trusted operators.
Reticle validates definitions, limits output, and applies timeouts. OS or server controls are still required for guaranteed termination.
Use restricted SSH principals and a dedicated, least-privileged daemon OS account. Viewers receive bounded results, never command text or execution controls.
Team serves authorized browsers, JSON clients, and read-only MCP. It exposes no browser terminal or ad-hoc shell.
Limit the daemon account, filesystem, environment, network reach, and SSH principals to what checks require.
Clients invoke persisted actions by ID, revision, and approval decision. They never supply command text.
The browser, JSON API, MCP, and chat expose no interactive or ad-hoc command interface.
Optional JSONL logging records selected connection, privileged-request, save-failure, and named-action events. It omits command text and output; records may include addresses, IDs, revisions, decisions, and errors. Protect and rotate the log.
Each subscription covers one running daemon and one topology. Access uses shared viewer and editor tokens; SSO and individual attribution are not included.
$199/month
Per running Team Daemon, billed monthly.
$1,999/year
Per running Team Daemon, billed annually.
$3,000one-time
Deployment, access controls, and initial mapping starts at $3,000 one-time.
We reply within one business day. Card, ACH, or bank transfer.
One daemon serves one topology. Team uses shared viewer and editor bearer tokens; SSO, individual identity, per-user attribution, built-in high availability, and a default SLA are not included. Audit logging is configurable, not automatic.
No. It places selected health evidence on the architecture people use to understand the system. Metrics, logs, traces, alerting, and durable history remain in their existing tools.
Team keeps collection always on, serves one current view to every browser, centralizes credentials on one host, and exposes authenticated JSON and read-only MCP.
Starting at $3,000, we help deploy the daemon, configure TLS and authentication, establish least-privilege access, and map the agreed initial production scope.
No default SLA is published. Support, updates, security review, and SLA requirements must be agreed before production adoption.
No. Desktop is free and MIT-licensed; Team Daemon is commercial subscription software.
Run Team Daemon yourself, or engage us to deploy it and map your first production scope.