Limits

What ArmorIQ Tools does not do yet, stated plainly, so you can evaluate it on the real picture.

The product claims to show you only what was really recorded. That principle is worth very little if the documentation oversells the product itself, so here is what is not built.

Not built yet

  • Approving held actions in the console. The Inbox shows you what is waiting, but you resolve it in the agent workflow that raised it. There is no approve or dismiss button.
  • Teams. No invites and no member list. One account, one workspace, one person. Roles do exist on the backend, and a workspace can mark you an admin or not, which is why a few actions can come back asking for an admin even though you cannot invite anyone.
  • Switching workspaces. Your account has exactly one.
  • Chat history. Conversations with AI Chat live in the browser tab and are gone when you leave.
  • Key scopes. You can scope a key to a product, but not to a set of permissions.

Built, in case you were told otherwise

  • Billing. Settings → Billing is real: Free and Pro, a monthly or yearly toggle, Stripe checkout, the customer portal, invoices and a promo box. Pro is $15 a month or $150 a year, flat, no per-call overage. Invoices are admin-only.

Rough edges

  • ArmorCodex is younger than ArmorClaude. The install path is less mature, and Policy Studio cannot sync a profile to it, because its current policy format does not support it. Codex sessions are still recorded.
  • Prompts are browser-local. They are saved per account and workspace in your own browser, not synced to anyone, and not installed into your agents. Export anything you care about before clearing browser data.
  • Some screens are reachable only by link or address. Tools, Runs, Agents, MCP Servers, Graph, Machines, Inbox, and Prompts are not in the sidebar.

Things that look like bugs and are not

  • Costs are estimates. They are computed from configured model rates, not from a bill. Usage with no configured rate is excluded, and the page tells you how many tokens that was.
  • A session with tokens but no tools. Historical token imports cannot reconstruct policy decisions, errors, or retries. The session is labelled rather than padded out.
  • A missing policy link on a call. It means that evidence was not reported for that call. It is not proof the agent was running unprotected, and the console will not claim either way.
  • P95 latency unavailable. Shown when there are fewer than 20 comparable calls, because a p95 over a handful of samples is noise.
  • A large latency number. Latency is turn wall time, which includes any period your machine was asleep in the middle of a turn.

Reporting something

If a screen shows you a number you think is wrong, the session detail view is the place to check it: it separates imported token usage from runtime tool evidence, so you can see which of the two disagrees.

On this page