# Speakeasy > Roadmap for Speakeasy. > Full content version — see https://roadmap.speakeasy.com/llms.txt for the index. ## Roadmap ### In Progress #### [Private Network Ingress (Tailscale first)](https://roadmap.speakeasy.com/request?id=ffe61091-fdfc-4688-9f51-2d5b70e00352) Enterprise-gated private MCP ingress through per-org Tailscale operator resources, workload-attested private serving, and per-server public/dual/private modes. --- #### [Shadow AI Monitoring](https://roadmap.speakeasy.com/request?id=4f305b1a-2866-48c2-8fbf-c07f7f7a7a86) Expand Shadow MCP support to Shadow AI detection specifically client use detection, with device agent support as a prerequisite. --- #### [Analytics API](https://roadmap.speakeasy.com/request?id=12c5b2d1-2ba6-4f35-9a47-96a282fb9327) Introduce a declarative endpoint for querying chat data, and all emitted metrics. --- #### [Killswitches](https://roadmap.speakeasy.com/request?id=382a4200-c004-4980-a364-733fd8ec6901) Allow admins to cut off access to AI by user/session/agent --- ### planned #### [Compliance as a conversation: Agentic ISO27001 Controls](https://roadmap.speakeasy.com/request?id=de869a55-d2e6-4bf4-af75-ff1fcf2498fc) Platform MCP capabilities so a compliance team's agent can implement ISO 27001 controls: policy redline + matching AICP configuration from one governed conversation. --- ### Scoped #### [Agent Lineage](https://roadmap.speakeasy.com/request?id=976a4843-4011-4c25-ad59-552e7f239229) Track and visualize the lineage of agent runs --- ### backlog #### [Antigravity coverage](https://roadmap.speakeasy.com/request?id=6f009b67-de0b-4a09-8618-363ea6e11077) Investigate and (if feasible) add Antigravity to supported MCP clients. --- #### [Zed coverage](https://roadmap.speakeasy.com/request?id=23511574-9c9b-4dab-aea3-7588259d4ed2) Add Zed as a supported MCP client surface for MoonPay POC follow-up. --- #### [Gemini Support](https://roadmap.speakeasy.com/request?id=5623d777-c4a9-4473-98ee-7c6fcabeef1f) Add support for usage tracking and plugin distribution to Gemini --- #### [URL Mode elicitation for Remote Sessions](https://roadmap.speakeasy.com/request?id=1ec921ee-a667-4073-822a-52159c0db218) --- ### completed #### [Agent Session Portability](https://roadmap.speakeasy.com/request?id=73e84f2f-1dfe-440e-980d-53e90f2e48b9) Pick a captured agent session from the Speakeasy tracked agent sessions and continue it in another harness (Cursor, Codex, Claude Code). --- #### [Device Agent: Request access for blocked AI tool calls](https://roadmap.speakeasy.com/request?id=b988a4b6-0b9a-4889-9785-db20e302b417) Turn shadow-MCP blocks into a desktop notification with a one-click access request that lands in the admin Approval Requests queue. --- #### [Remote Authentication Branding](https://roadmap.speakeasy.com/request?id=3d3f9ec1-cb1d-4acf-b2af-5653d677e3fd) End users see a logo and display name when challenged to authenticate against an external service, and administrators see that branding across the management UI. Requires expanding asset management to organization and platform tiers. --- #### [Prompt Injections Scanning in Skills](https://roadmap.speakeasy.com/request?id=dfe0fbc0-1373-4ca2-9771-811973618d84) --- #### [Prompt Based Policies: Policy Suggest, Hybrid & Session Quarantine](https://roadmap.speakeasy.com/request?id=fbaaf0bd-a9de-48ef-9141-1613e549409d) Derive policies from sampled activity (Policy Suggest), layer static rules ahead of the judge (hybrid), widen coverage beyond tool calls, and async session quarantine with tool blocking. --- #### [Prompt Based Policies: Policy Evals (Session Replay)](https://roadmap.speakeasy.com/request?id=067c4c06-1287-40ba-b4f8-929727555fe0) Non-enforcing replay of prompt-based policies over historical sessions + a review workbench, so authors can gauge efficacy and build a regression set before activation. --- #### [Platform-level remote identity providers](https://roadmap.speakeasy.com/request?id=b659e33e-e3d2-4da3-9ecd-5bf15a187902) Make the existing global remote_session_issuer tier resolvable by tenants, curated by platform admins, and reachable by migration from duplicative org/project issuers. --- #### [Tool Drift Detection](https://roadmap.speakeasy.com/request?id=82476a50-2469-433f-be57-15e8b3a91b48) Persist per-tool MCP annotations so RBAC can make disposition-aware decisions in the remote-MCP proxy without fetching tools/list upstream on the hot path. --- #### [Multiple Remote Sessions per MCP Server](https://roadmap.speakeasy.com/request?id=a7ed48e1-d3a9-469e-afac-905e7c4712a0) Support multiple remote authorizations and standalone remote authorization client creation. --- #### [BYOK for Managed Inference (OpenRouter)](https://roadmap.speakeasy.com/request?id=fbfd7993-7e7f-4e8e-a368-77bbc0eeb5c0) Let customers bring their own Openrouter keys for the Assistants, Risk Policies and other inference capabilities on the platform. --- #### [MCP Risk Approval](https://roadmap.speakeasy.com/request?id=096c55b2-5732-45e3-bf32-7f34fd56efd3) A request-and-approve workflow for unverified MCP servers: evidence assembled automatically, an optional research agent, and a decision recorded with an explicit blast radius and a defensible rationale. --- #### [OpenCode support](https://roadmap.speakeasy.com/request?id=b3247a1c-27ec-483d-a652-2f0d69a3b686) Extend AI Control Plane hooks coverage to OpenCode for MoonPay POC follow-up. --- #### [OAuth CIMD Support](https://roadmap.speakeasy.com/request?id=e0ede263-399d-470e-a812-761bc8d22d20) CIMD lets OAuth clients use an HTTPS URL as their `client_id`. The authorization server fetches that URL on demand and treats the returned JSON document as the client's "registration." It removes pre-registration friction in the no-prior-relationship case --- #### [Security: Confirm / Warn policy type](https://roadmap.speakeasy.com/request?id=358d8a5a-877f-4087-901c-8c3a6abbd097) New policy setting. In addition to flag and block we provide confirm for users to self approve flagged actions to unblock themselves. These are still logged to the admin for review. --- #### [Assistants Beta Release](https://roadmap.speakeasy.com/request?id=64ce5e34-b6fc-4dfa-a9b5-3409372a2028) Graduate Assistants from Early Access to Beta --- #### [MCP Network-Level Access Control](https://roadmap.speakeasy.com/request?id=fb05ad55-fce6-48eb-9015-952e12f89722) Add network-level access controls for MCP servers via configurable ingress rules and tailnet-aware access. --- #### [Gram: Support Custom Code for Tools (aka "Gram Functions)](https://roadmap.speakeasy.com/request?id=e2361707-7921-4d9b-8299-4352db666235) Support agentic tools defined in code in Python and Typescript --- #### [Gram: Support spec uploads without operationIds](https://roadmap.speakeasy.com/request?id=f54ed4b7-a234-414b-bc19-73682298649b) --- #### [Gram: CLI v0.2.0](https://roadmap.speakeasy.com/request?id=bd97eec2-5127-488d-9daa-ce523b7183c1) Better documentation, homebrew support, ability to check deployment status and toml/yaml config support. --- #### [Gram: Faster Deployments](https://roadmap.speakeasy.com/request?id=54d6b4ba-cfc6-4bec-878c-1eaf5bfef650) Process all customer deployments under 10 seconds --- #### [Gram: Customer Configured MCP Install Page](https://roadmap.speakeasy.com/request?id=5e597ec6-4596-4d3e-ae56-e18bef936d93) Allow users to specify external docs and custom logos for public MCP install pages --- #### [Remote MCP Support](https://roadmap.speakeasy.com/request?id=5e7dca99-3064-45e3-8ff7-48734f14bdda) Support proxying and collecting metadata on requests from MCP servers hosted outside of Gram --- #### [Skills Management](https://roadmap.speakeasy.com/request?id=10358172-519c-4f2b-8700-d3d9fe57ba09) Observability, distribution, and governance around skill usage for an organization. --- #### [MCP Logs dashboard improvements](https://roadmap.speakeasy.com/request?id=435ac366-bb9b-47a0-bf07-585bf3c3f15a) Improving the search and table views in /logs/mcp --- #### [Shadow MCP Request Approval Flow](https://roadmap.speakeasy.com/request?id=0878a2a6-1fa0-4c7e-b1d9-11cee5373e68) Dashboard and Webhook powered request - approval flow for shadow server compliance --- #### [Security: Prompt based policies](https://roadmap.speakeasy.com/request?id=7e7a62a9-0795-4e9f-b529-3a9afee7f0b7) --- #### [Environment UX Improvements](https://roadmap.speakeasy.com/request?id=3adab8ff-35d7-4010-bf2e-e7a92777fee8) --- #### [Workforce Observability Dashboard](https://roadmap.speakeasy.com/request?id=3db15bc1-10f7-4020-a4a2-296a8d3549f4) Employee compliance and token usage --- #### [RBAC for risk policies](https://roadmap.speakeasy.com/request?id=69516ff3-e78f-47d8-890b-28c664bc3d24) Using the RBAC system for policy audience assignment --- #### [MCP Server Tool Filtering](https://roadmap.speakeasy.com/request?id=1a22c519-9b94-4c44-8269-ba655197cbca) Enhance Hosted MCP Server endpoints to support filtering of tools and resources by a tool parameter. --- #### [Support organization-level remote session issuers](https://roadmap.speakeasy.com/request?id=480fcc52-2a60-4735-8b92-68610d2c1a84) Customers will want cross-project management of certain remote session issuers, such as company-owned OAuth servers, to prevent duplication and simplify MCP Server management. --- #### [Requests & Approvals](https://roadmap.speakeasy.com/request?id=dea38a3a-6d2a-40a5-ae29-09123fb388bf) Gives workspace admins visibility and control over Shadow MCP policy blocks — review, approve, or deny access requests and manage allow rules from the dashboard. --- #### [Anthropic Compliance API Integration](https://roadmap.speakeasy.com/request?id=9dcad6d2-fa58-46ff-919c-fa19b23d0e41) Previously known as Anthropic Compliance API integration. --- #### [Platform MCP and Plugin](https://roadmap.speakeasy.com/request?id=a052a6ca-13db-4d2e-9e1a-18a8d8c1f966) First-party Platform MCP plus published agent plugins (MCP and skills) that let customer org admins run day-to-day Gram administration headlessly from Claude, Cursor, Codex and other harnesses. --- #### [Exclusions and retroactive suppression of risk findings](https://roadmap.speakeasy.com/request?id=ca5d3020-c6d6-4a8a-94f1-46be908d86c7) Given some risk finding in the dashboard that a user doesn't find useful they can select and suppress it such that it does not appear again in the future nor will it impact aggregations --- #### [Personal Account Tracking](https://roadmap.speakeasy.com/request?id=845f5e68-115e-41ee-a70b-8b7bee285d5f) Offer visibility into personal account usage on company devices --- #### [Private MCP Tunnels](https://roadmap.speakeasy.com/request?id=2598882f-8707-4c37-ad14-c1c133e18b43) Tunnelling functionality in order to make customers VPC/On prem services data accessible from Speakeasy hosted MCPs --- #### [Cost: Tool- & MCP-level Cost Tracking](https://roadmap.speakeasy.com/request?id=e0e2281f-ae27-4f9a-b6c2-762ff96872e7) --- #### [Streaming and Bulk export of data feeds](https://roadmap.speakeasy.com/request?id=6d97cb57-7639-4717-b662-e42d96c271ff) Create a scalable way to export customer data from AICP to customer-specified destination. Includes agent sessions and risk findings. --- #### [Shadow MCP Inventory](https://roadmap.speakeasy.com/request?id=0c91952c-1fa9-46e3-bf76-7ca50c153cfa) Expand Shadow MCP request&approval to complete inventory of all shadow servers and analytics --- #### [[Risk UX] Watchdog: Signals, Ranking, Triage](https://roadmap.speakeasy.com/request?id=94cbeccf-e4ac-4045-9628-57905ac99687) Observability and Reactions dashboard for admins --- #### [Risk Finding Severity](https://roadmap.speakeasy.com/request?id=c6e5e262-b5d1-4ab7-8d2d-2b0ab4fb9b94) Allow users to specify the severity for findings identified by a given risk policy --- #### [Shadow MCP Policy Gates](https://roadmap.speakeasy.com/request?id=187ae344-a0df-4c92-9123-f4b5b477fb8d) Gives admins a choice to Allow All or Block All as the default disposition when creating a Shadow MCP policy, with block rules as the inverse of today's allow rules --- #### [LiteLLM Usage Integration](https://roadmap.speakeasy.com/request?id=e71a25c3-fdc1-4599-8f5b-2606e5f89f0a) Customers can bring their existing LiteLLM usage to the platform to track for Observability, Security and Cost budgeting. --- #### [Pre-emptive Remote Session Refresh](https://roadmap.speakeasy.com/request?id=b21d2c25-2807-48b6-a272-8d2f905ea93c) --- #### [End User Tool Filtering](https://roadmap.speakeasy.com/request?id=4daa2d6b-c50c-4de2-bf4e-d2ed23baa0e1) if an MCP server is hosted or proxied by speakeasy, when authenticating, it's possible for a user to authenticate specific annotations of tools, and/or specific tools. Does not override permissioned based access to tools through RBAC. --- #### [Plugin Distribution for Directory Groups](https://roadmap.speakeasy.com/request?id=dd27ebb4-6d73-4202-8692-149d412bb307) ---