V1.0 macOS 14+ · your data stays on your Mac · no account

Control starts with visibility.

Your AI tools have more ways to act than you think. Mockingbyrd maps those capabilities, sets the boundaries, and tells you when they change.

Download for macOS Read the doctrine Apple silicon · macOS 14+ · signed and notarized
AI
DOCTRINE SCORE 41/ 100
17 of 46 rules failing
PERMISSIONS HELD 312grants 4 wildcard · 0 that refrain
GUARD · LAST 24H 2,481calls inspected before running
6 refused · 1 paused 12m
DRIFT hooks.json changed 04:12 no longer matches the
configuration you approved

DEMO MACHINE · SYNTHETIC RULE PACK

HOW IT WORKS04 STEPS
THE ORDER IS
LOAD-BEARING

Measure first. Change nothing you haven't verified.

01

Measure

Checks run against the actual machine — permission lists, file flags, hooks, snapshots, open database handles. Each reports the evidence it found, not a green tick. The result is a weighted score you can argue with.

02

Implement

Every fixable finding writes a shell script and shows it to you. Read it, then apply — or run it yourself. Settings are backed up before a byte changes.

03

Enforce

A hook inspects every tool call before it runs, reading the command and the paths it touches. It sits below the permission list, where a wildcard grant can't step around it.

04

Watch

Re-scans on your cadence. Says when a control that was holding stops holding, when a config file changes underneath you, when the original moves and nothing was supposed to be writing to it.

THE ROSTER · 08 CAPABILITIES PER AGENT

Every agent on this Mac, and what each one can reach.

Sessions, subagents, scheduled jobs, connectors — the roster names which kind each one is rather than flattening them, and fills a cell only from something on disk: a permission entry, a profile, an agent definition, a scheduled job, a connector declaration.

The combinations that matter are named underneath each one: reads widely and can send off the machine, runs arbitrary code, runs unattended while nobody is watching.

Connectors enabled in the web app are configured server-side, so a locally declared list is a floor, not the whole picture. The roster says that on the screen rather than in a footnote.

DEMO MACHINE · SYNTHETIC AGENTS

The Agent Roster: ten agents wired to a hub marked This Mac, each card listing what that agent can reach.
WHAT YOU GET06 CAPABILITIES

A score, not a checklist

Controls are weighted by what they cost you when they fail, so the number moves for reasons you can name. Every check shows its working.

Fixes you read first

No silent remediation. The change is written to disk as a script you can open, before anything runs it.

Enforcement below the config

A permission list sitting beside a general interpreter is advice. The guard reads the command whichever interpreter would have run it.

Pause that actually pauses

The guard re-reads its state on every call. Pause takes effect now, resumes itself when you said it should, and keeps logging throughout — so you can see what went through while it was off.

Drift you'd otherwise find late

Fingerprints on the files that matter. A control that quietly stopped holding is an event, not something you discover in a quarterly review.

Your doctrine, not ours

Ships with one rule pack. Every rule is a shell probe you can edit, weight, disable or replace — write your own and the score follows.

THE LEDGER · READ LOCALLY, SENT NOWHERE

What the agents cost, rebuilt from files already on disk.

Token use and API-equivalent spend by model, by project, by week — read from the session logs your agents already write. Producing it sends nothing anywhere.

It scores the waste too: whether caching is working, connectors that sit unused while adding their description to every prompt, agents spending unwatched, and sessions picked up cold when a fresh one would have been cheaper.

It is not a bill. Neither a Claude nor a ChatGPT subscription is billed per token — this is what the same traffic would have cost at list prices, which is a sense of proportion rather than an invoice.

DEMO MACHINE · SYNTHETIC SESSIONS

The Token Ledger: API-equivalent cost, model calls and sessions, with weekly charts and a breakdown by model and project.
TWO MODESONE SET OF
NUMBERS

The same data, twice.

Nerd Mode is the probes, the weights and the evidence: the seven rules that do not bend, the rollout behind them, every control with the shell probe that tested it and its result across the last 24 scans.

Intuitive is plain language over identical numbers — areas instead of invariants, a card per finding, the map without the matrix, and one button that separates what can be fixed for you from what needs you.

Neither is a subset that hides a problem. The mode changes the vocabulary, not the score.

INTUITIVE
Intuitive mode: a coverage dial reading 30 percent, four area cards, and a Fix button.
NERD MODE
Nerd Mode: the same scan as weighted control coverage, the seven invariants with per-rule percentages, and the rollout phases.

THE SAME SCAN, BOTH MODES · DEMO MACHINE, SYNTHETIC RULE PACK

Hear when the build changes.

The download above is current. Leave an address and you will hear when there is a new one worth installing — not before.

Used for that one email and nothing else.

Request an activation code

Mockingbyrd runs for seven days without one. Leave an address and we will send a code back — during the test phase they are issued by hand, so allow a day.

Used to send you a code and nothing else. If you have already installed the app, reply with the machine code from Settings and the licence will be tied to that Mac.

Request the documentation

What each rule probes and how it is weighted, what the guard reads before a call runs, and where the controls stop. We will send it over.

Used to send you the documentation and nothing else.