Features · Session reports

Every session,
explained.

The moment your agent finishes, Backplanes writes the report you would never write yourself: what it built, what it touched, and the few things that deserve your eyes. Skim it in a minute.

Free · Claude Code, Codex and Cursor · No agent changes

← Back to my reportsSession 1A2B3C · Export PDF
High

CI scanner v0 shipped to production

Shipped working, but the agent wrote an API key to disk and read 47 files outside the project boundary. End-to-end scanner, daily cron, dashboard wiring, live HTML render.

dougMay 9, 17:31 to May 11, 20:38
  • 51h 7mDuration
  • $230Est. cost
  • 5Findings
  • 566Actions taken
  • 13Sub-agents spawned

Where the time went51h 7m total · classified by tool category

  • Code 51%
  • Shell 46%
  • Research 2%
  • Review 1%
  • Idle 0%

What it is

A session report is the write-up Backplanes generates the second your agent stops: a verdict, the findings worth acting on, where the time went, and the full story of the run. Nothing to check. It is waiting when you get back, and it is where your first controls are drawn from.

Anatomy of a report

One page tells you everything.

Built to read top to bottom in about a minute: the verdict first, the receipts underneath. Here is what each part is doing for you.

← Back to my reportsSession 1A2B3C · Export PDF
High

CI scanner v0 shipped to production

Shipped working, but the agent wrote an API key to disk and read 47 files outside the project boundary. End-to-end scanner, daily cron, dashboard wiring, live HTML render.

dougMay 9, 17:31 to May 11, 20:38
  • 51h 7mDuration
  • $230Est. cost
  • 5Findings
  • 566Actions taken
  • 13Sub-agents spawned

Where the time went51h 7m total · classified by tool category

  • Code 51%
  • Shell 46%
  • Research 2%
  • Review 1%
  • Idle 0%

Common checks1 needs action · 5 clean

  • !Credentials exposed
  • Auth and access clean
  • External calls observed
  • Production config clean
  • Sandbox discipline holding
  • Skills clean

Where this happened

doug · scanner-platform · claude hosted · claude-opus-4-7 · reasoning: extended · repo platform/scanner

Take action now 2 findings

A1

credential API key written to disk and echoed across 14 shell commands

Key sk_live_7a3b…2f0c was written to ~/.config/scanner/env during setup, then echoed across 14 shell commands. Your env file and shell history both hold it in plain text. Rotate it before anything else.

A2

scope Agent reached into 47 files outside the project, including your home config

The agent read 47 files in ~/.config and ~/.local/share that sit outside the platform/scanner repo. Nothing left the machine, but its reach is wider than declared. Narrow the workspace before the next run.

Worth a look 2 findings

W1

pattern SSH key reached from three different sub-agents

Three independent sub-agents read the same private key at ~/.ssh/id_ed25519_agents over the course of the session. Not a violation today, but worth a control on cross-sub-agent credential reuse before it becomes one.

W2

redacted Slack bot token caught in console output before upload

Token xoxb-•••••••• was printed to console during a sub-agent dispatch. It was redacted from the uploaded transcript, but the original is still in your local terminal scrollback.

Patterns to keep 1 from this session

P1

habit Always checked the network before reaching for it

Verified SSH, peer status, DNS and reachability before any remote write. Three runs would have failed deep into work; instead they failed safely up front, and nothing had to be rolled back.

Story of the session20 events · 13 sub-agents · 5 findings

  • d1 04:52Sub-agent returned · pre-flight network checksmain
  • d1 08:45Sub-agent returned · dashboard scaffoldmain
  • d2 09:21Sub-agent returned · digest format and source listmain
  • d2 09:24Sub-agent dispatched · render HTML report from scanmain
  • d2 14:04Git push · -u origin scanner/v0-pipelinemain
  • d3 11:27Sub-agent succeeded · end-to-end smoke testmain
  • d3 20:38Finding flagged · API key written to diskmain
  • d3 20:38Finding flagged · file reads outside project boundarymain
  • Show 12 more events ↓

Sub-agents

Sub-agent returned

subagent · digest format and source list

When
2026-05-10 05:21 UTC
Actor
main
Status
completed
Agent id
a4d7…f9a7a1e01
Tool
Agent
Result
summary returned
  • 1Read
  • 0Search
  • 0Bash
  • 0Edit
  • 0Other

Security

  • Session observed100%
  • Issues we flagged5
  • Credential-related actions5
  • Risky-looking commands0

Activity

  • Shell commands run294
  • File reads and writes318
  • Web searches10
  • MCP servers called0

What changed

  • New files created112
  • Existing files edited72
  • Unique files seen197
  • Config files changed1

End of report · 1A2B3C2B-087D-4369-8F12-529E2F73B4E3

Findings

Catch what you'd never scroll to find.

The few moments that need you, pulled from the whole transcript, with the fix attached.

  • Credentials written to disk, echoed to shell, caught in output
  • Files reached outside the task
  • A one-click next step on every finding

Take action now 2 findings

A1

credential API key written to disk and echoed across 14 shell commands

Key sk_live_7a3b…2f0c was written to ~/.config/scanner/env during setup, then echoed across 14 shell commands. Your env file and shell history both hold it in plain text. Rotate it before anything else.

A2

scope Agent reached into 47 files outside the project, including your home config

The agent read 47 files in ~/.config and ~/.local/share that sit outside the platform/scanner repo. Nothing left the machine, but its reach is wider than declared. Narrow the workspace before the next run.

Time and effort

See where the hours actually went.

Every minute classified, and the time you would want back named.

  • Split by code, shell, research and review
  • Faster next time: time-savers ranked by minutes
  • The honest denominator behind cost

Where the time went51h 7m total · classified by tool category

  • Code 51%
  • Shell 46%
  • Research 2%
  • Review 1%
  • Idle 0%

Patterns

Keep the habits worth keeping.

What your agent did well is named too, so good runs compound.

  • Good habits named, not just failures
  • Save as habit to hold the next run to the same bar
  • The receipts behind “it shipped clean”

Patterns to keep 1 from this session

P1

habit Always checked the network before reaching for it

Verified SSH, peer status, DNS and reachability before any remote write. Three runs would have failed deep into work; instead they failed safely up front, and nothing had to be rolled back.

The payoff

What you get, every session, without asking.

None of these is a measured outcome. They are what the product does.

100%
of the session observed, nothing left to memory
1
command to install, with no changes to your agent
0
dashboards to check. The report is waiting when you get back
3
harnesses today: Claude Code, Codex and Cursor
I just want to know where the hell it’s going.

CISO · healthcare AI startup

Get started

See what your last session actually did.

One command. Your first report lands within minutes, free for you and your team.

curl -fsSL https://www.backplanes.com/spotlight/install.sh | sh