Two products, one platform
Which one do I need?
Start with the Egret agent - it works completely standalone. Add Egret Nest later if you want history and a fleet view. Here's who does what.
| Egretthe agent | Egret Nestthe dashboard | |
|---|---|---|
| What it is | The agent that runs your build | A dashboard for your runs |
| Runs on | Your CI runner / Linux host | Your own server (self-hosted) |
| eBPF egress / process / file monitoring | ✔ | · |
| Egress enforcement (block mode) | ✔ | · |
| Audit-mode policy generation | ✔ | · |
| Reports (Markdown / JSON / SARIF) | Writes them | Ingests them |
| History across runs & repos | · | ✔ |
| New-endpoint drift | · | ✔ |
| Org RBAC + multi-user | · | ✔ |
| Auth (local+TOTP / GitHub / OIDC) | · | ✔ |
| Ships as | CLI + GitHub Action | Docker image / Go binary |
| Required? | The core product | Always optional |