RETICLE TEAM DAEMON

Give the whole team one infrastructure diagram that stays live.

Run one daemon inside your network. It keeps your Git-tracked operating map current and serves the same context to every authorized browser, internal tool, and read-only agent.

One topology · Unlimited teammates · One trusted network vantage point · Credentials stay on one host

A REAL TEAM DIAGRAM, KEPT LIVE

Explore the architecture serving reticle.live.

This is the hand-authored diagram we use to understand reticle.live, connected to current health evidence from the Team Daemon it describes. The public browser is read-only.

Pan, inspect, and export the diagram. Read-only access is enforced by the daemon. Open full screen ↗

WHY TEAMS UPGRADE

Keep the diagram available beyond one laptop.

Desktop and Team use the same intentionally defined model. Team keeps collection running and makes one current view available across the organization.

Always available

The operating diagram stays live independent of any one engineer's laptop.

Shared understanding

Teammates inspect the same topology, evidence, notes, and timestamps from a browser.

Centralized access

Checks run from one managed host. Viewers and read-only integrations get context without receiving SSH credentials or shell access.

TEAM OUTCOMES

Give every responder the same architecture.

FASTER INCIDENT UNDERSTANDING

See the system around the failure.

Keep dependencies, current evidence, notes, and freshness in one shared browser view.

LESS TRIBAL KNOWLEDGE

Share the model, not a verbal reconstruction.

New operators and escalation paths can inspect the architecture without waiting for its original author.

SAFER NEXT ACTIONS

Keep evidence beside the response.

Persist bounded actions with approvals, timeouts, and optional fresh-signal preconditions.

PRODUCT SPLIT

Desktop for one person. Team for the organization.

Reticle Desktop compared with Reticle Team Daemon
CapabilityDesktopTeam Daemon
DeploymentStandalone, local-only appAlways-on daemon on your infrastructure
AccessOne local operatorUnlimited browser seats
IdentityLocal OS userShared editor/viewer bearer tokens; SSO is not included
Topology scopeMultiple local workspacesOne topology per licensed daemon
UI and integrationsLocal UI; loopback JSON API; read-only MCPBrowser UI; authenticated JSON API; read-only MCP
ChecksFixed checks; optional privileged commandsFixed checks; gated custom commands
ShellLocal privileged shell availableNo Team shell
Audit logsNot a shared serviceJSONL when --audit-log is configured
LicenseFree, MITCommercial subscription
WHITE-GLOVE IMPLEMENTATION

Turn the architecture your team knows into the first live topology.

Starting at $3,000 one-time, we deploy the Team Daemon, establish TLS and access controls, and map the agreed architecture from your existing diagrams, runbooks, and operator knowledge.

01

Deploy

Install the daemon on a trusted host inside your network and configure TLS.

02

Constrain

Set viewer and editor access, least-privilege OS permissions, and restricted SSH principals.

03

Map

Build the first agreed operating diagram and connect its initial health checks.

CONTROLLED ESCALATION

Custom checks require explicit trust.

Fixed HTTP and read-only SSH checks remain the default. Custom remote SSH or local Bash checks run only when the operator enables them.

01

Operator opts in

Start the daemon with --allow-custom-commands.

02

Trusted configuration

Editors manage definitions. New checks are enabled and viewer-visible by default; named actions require approval by default. Direct YAML writers are trusted operators.

03

Bounded execution

Reticle validates definitions, limits output, and applies timeouts. OS or server controls are still required for guaranteed termination.

Custom commands are arbitrary, not inherently read-only.

Use restricted SSH principals and a dedicated, least-privileged daemon OS account. Viewers receive bounded results, never command text or execution controls.

CONTROLLED BY DESIGN

Share the diagram without sharing shell access.

Team serves authorized browsers, JSON clients, and read-only MCP. It exposes no browser terminal or ad-hoc shell.

Constrained access

Limit the daemon account, filesystem, environment, network reach, and SSH principals to what checks require.

Server-owned actions

Clients invoke persisted actions by ID, revision, and approval decision. They never supply command text.

No Team shell

The browser, JSON API, MCP, and chat expose no interactive or ad-hoc command interface.

Configurable audit logging

Optional JSONL logging records selected connection, privileged-request, save-failure, and named-action events. It omits command text and output; records may include addresses, IDs, revisions, decisions, and errors. Protect and rotate the log.

SIMPLE PRICING

One topology. Unlimited seats.

Each subscription covers one running daemon and one topology. Access uses shared viewer and editor tokens; SSO and individual attribution are not included.

Monthly

$199/month

Per running Team Daemon, billed monthly.

Implementation

$3,000one-time

Deployment, access controls, and initial mapping starts at $3,000 one-time.

Start with Team

We reply within one business day. Card, ACH, or bank transfer.

Current boundaries

One daemon serves one topology. Team uses shared viewer and editor bearer tokens; SSO, individual identity, per-user attribution, built-in high availability, and a default SLA are not included. Audit logging is configurable, not automatic.

FAQ

Deployment and product questions

Does Reticle replace monitoring or observability?

No. It places selected health evidence on the architecture people use to understand the system. Metrics, logs, traces, alerting, and durable history remain in their existing tools.

Why use Team instead of sharing the YAML?

Team keeps collection always on, serves one current view to every browser, centralizes credentials on one host, and exposes authenticated JSON and read-only MCP.

What does white-glove install and mapping include?

Starting at $3,000, we help deploy the daemon, configure TLS and authentication, establish least-privilege access, and map the agreed initial production scope.

Is an SLA included?

No default SLA is published. Support, updates, security review, and SLA requirements must be agreed before production adoption.

Is Team Daemon MIT-licensed?

No. Desktop is free and MIT-licensed; Team Daemon is commercial subscription software.

Give the team one shared operational map.

Run Team Daemon yourself, or engage us to deploy it and map your first production scope.