Your team codes with AI now. Measure like it.
AI-native engineering analytics
Tempo reads the work itself: Claude Code and Codex sessions and the git history where the work landed, alongside the goals your team approves. It shows you what your team declared, what shipped against it and what that cost. The dashboard does not need screenshots or transcript message bodies to do any of it. Tempo’s desktop collector sends structured metadata to Tempo, not transcript message bodies.
Tempo measures the two coding agents it can read end to end: Claude Code and Codex. That includes the subscription seats no admin API can see, because the measurement comes from the session record rather than from a billing export. Where a vendor does not record the branch a session was on, Tempo says so on the cell rather than guessing at the join.
The work already has a chain. Tempo follows it.
Discussion to target to work to session
Alignment is not a score. It is four links, and each link is a row somebody can open: the discussion that set the direction, the target ratified from it, the work declared against that target, and the sessions that produced the work. Any claim about your team is only as strong as the weakest link beneath it, so Tempo shows you the links rather than the summary.
- Slack discussions (deferred) → The retained development path reads a discussion only from a channel an administrator has bound to a team. Slack integration and live-install acceptance remain deferred. Slack is not part of the supported onboarding path. Targets can be written and approved by hand; a goal without source evidence carries no citation.
- Team targets → Where discussion evidence is available, a target proposed from it and ratified by a person, carrying the citation and its stable source pointer: the channel and message timestamp, never a stored excerpt. A manually written target needs no discussion. Nobody has ratified a target for this team. The alignment view answers not_measured and names ratification as the remedy, rather than ranking work against a list that does not exist.
- Tasks and pull requests → Issues and pull requests from your GitHub organisation, projected into declared work and joined to the target they were opened against. The repository is connected but nothing in the window references a target. The work is still listed, listed as undeclared, with the link that would fix it attached to each row.
- Sessions → Claude Code and Codex sessions, joined to the work by repository, branch and time, with cost and attended hours attached. No session joined to this work. The cost cell reads not_measured and gives the reason: no collector on that machine, or a vendor that did not record the branch.
An empty link is an answer, not an error. It names which link is empty, why it is empty and what would fill it. Tempo does not estimate across a gap, does not drop the row, and does not answer a missing link with a 404.
Commit counts stopped meaning anything. Substance didn’t.
Analytics that survive the AI era
When AI does the typing, volume is free. A week of easy pull requests costs almost nothing to produce and tells you almost nothing once produced. Tempo scores what mattered: the work that landed, against the targets your team ratified, and whether it stayed landed.
- Work-level scoring. Work is grouped into features and scored on quality times importance, so mediocre output nets zero and a broken launch on a critical surface scores below zero. The rubric is shown with the score, and a score without its rubric is not rendered at all.
- Importance you ratified, weighting anyone can read. The weights come from the team targets in the chain, each openable back to the discussion it was proposed from. A target nobody ratified carries no weight, which is what makes a low valuation appealable.
- Churn and rework detection. Reverted work, repeated fixes to the same subsystem, pull requests that stall or get superseded. The pattern arrives as a flag with its evidence attached, never as a silent penalty buried inside a number.
- Who steers the agent, and who ships its output unread. On a team where everyone uses AI, usage share tells you nothing. What separates people is whether they validated what the model produced, and the session record shows that wherever the sessions exist. Where they do not exist, the answer is not_measured rather than a low score.
- Two windows, always. Full period and trailing weeks, side by side, so an old mistake cannot bury a strong recent quarter and a hot streak cannot hide an old mess either.
- The ledger ranks work, not workers. The screen is a list of shipped things, most expensive first, each with the sessions and the branch that prove its link. Teams are compared at month granularity, and a cell below the noise floor reads insufficient_power with the volume it would need, rather than a provisional rank.
| Release guardrails | weighted +5.0 | Illustrative data. |
|---|---|---|
| Payment retry queue | weighted +3.5 | Illustrative data. |
| Search reindex | weighted 0.0 | Illustrative data. |
| Billing migration | not_measured | Illustrative data. |
Illustrative data. The ranking is of work items and never of people. Work the chain cannot join is listed as not_measured rather than dropped, because a ledger that hides its gaps reads as a complete one.
- ⚑ Re-fix loop
- The same subsystem was patched again and again across the window without a durable fix landing. The flag lists the pull requests and the sessions attached to it, and it stays a flag: it is never quietly deducted from anybody’s number.
- ⚑ Shipped unread
- Agent output committed with no validation step anywhere in the session. The flag cites the sessions and the commits, and it says plainly when the sessions it would need are the ones that are missing.
Know what your AI spend bought. Not just what it cost.
Cost governance
Most teams can say what they spent on models last month. Very few can say what it bought. Tempo attributes spend to people, projects, vendors and models, then follows it down the chain to the work that actually landed.
| Claude Code | $18,300 | Illustrative data. |
|---|---|---|
| Codex | $5,400 | Illustrative data. |
| Unallocated | $1,100 | Illustrative data. |
Illustrative data. Model and vendor labels are the ones your own sessions record; Tempo does not invent a tier your vendor never reported. Subscription seats are priced from public per-model pricing, which is an equivalent-value estimate rather than an invoice.
| Declared budget | $60,000 | Illustrative data. |
|---|---|---|
| Spend so far | $38,900 | Illustrative data. |
| Elapsed | day 18 of 30 | Illustrative data. |
Illustrative data. The budget is the one your organisation declared; Tempo does not infer a budget nobody set, and a project with no declared budget gets no burn flag rather than a guessed one.
- Cost per thing shipped. Spend is attributed through sessions to the work that landed, which turns a monthly total into a price per delivered item. Where one session touches several pull requests the split is fractional and the remainder sits in an explicit unallocated bucket, because charging a session whole to each of them inflates every price on the page.
- Every seat, including the subscription ones. Subscription seats are invisible to every official admin API. Tempo measures from the session record instead, which puts the whole team on one ledger. Subscription cost is an equivalent-value estimate computed from public per-model pricing; it is not an invoice, and it is labelled as an estimate wherever it appears.
- Spend by person, project, vendor and model. Find the workflow burning a frontier model on work a small one handles perfectly well, and the engineer whose agents replaced a week of somebody else’s time. The vendor split rides along on every mixed cell, because a mixed cell without it measures tool choice rather than cost.
- ⚑ Burn-rate flags. They fire while there is still month left to act on them, whenever a project tracks over the budget it declared, and they arrive with the sessions that drove them attached.
- Your analysis costs stay yours. Deep-dive analysis runs through the coding agent and the model you already pay for. Tempo does not meter your questions.
Ask it where you already work. Argue with the answer.
The part no dashboard can do
Tempo ships as a remote MCP server over Streamable HTTP, for Claude Code, Codex and any other agent that can complete an OAuth flow. A dashboard shows you charts. Tempo answers a question inside the tool you already have open, and every claim it makes carries the sessions, commits and pull requests it was computed from.
› how did the release guardrails work land, and what did it cost?
Release guardrails · trailing weeks
Declared against target “ship the release gate”, ratified from #eng-planning
Work two pull requests, both merged
Sessions joined by repository and branch, Claude Code and Codex
Cost equivalent-value estimate, public per-model pricing
Attended not_measured on one machine: no collector installed
Blind spots: review activity is not scored; one session carries no branch,
so its cost sits in the unallocated bucket rather than on this item.
Every line above cites the sessions, commits and pull requests behind it.- Ask a question, get an answer. “Which work is carrying this quarter’s targets?” “What did the auth rewrite cost?” “Is anyone stuck in a rework loop?” Plain language in, evidence-backed answer out.
- Citations on every claim. Session identifiers, commits, pull request numbers. A negative finding runs a refute-first pass before anybody sees it, and no number is shown without its rubric, its caveats and a list of what the data could not see.
- Bring your own frontier model. Analysis runs through the agent and model you already use, so you keep control of both the model and the subscription, and Tempo never meters your questions.
- Writes are inert until a person confirms them. An agent can propose a team target from a discussion; it cannot ratify one. The proposal does nothing until a member of your organisation confirms it, which is also what makes the resulting target appealable later. A message that tries to steer the agent into writing a target for you gets no further than a candidate row.
Not bossware. Verifiably.
Transparent by design
The monitoring industry trained everyone to expect stealth modes and screenshots. We built Tempo so that its privacy claims are architectural facts rather than settings: things that cannot be switched on, because the code that would do them was never written. Your security team can check every one of them in the product itself.
Tempo’s desktop collector sends structured metadata to Tempo, not transcript message bodies. That metadata describes which tools ran, for how long, against which repository and branch, at what cost. Separately, the local coach returns requested transcript excerpts to your AI client, which may send them to its configured provider. Tempo never stores your code, your prompts, or your chat messages — only counts, timestamps, and the goals you approve. There is no table for a message to sit in. The retained Slack development path reads a bound channel only when requested and keeps no message body. Tempo keeps the goal a person approves and a stable reference to its source channel and message timestamp when there is source evidence. Slack integration and live-install acceptance remain deferred.
- Metadata only.
- The desktop collector uploads structured metadata, not transcript message bodies. What Tempo holds about a session is a record of shape, timing and cost. This collector boundary does not describe what your AI client does with excerpts requested from the local coach.
- No screenshots. No screen recording.
- The code to capture a screen was never written, so there is nothing to switch on. The same goes for desktop activity: Tempo does not read window titles, application usage or the accessibility tree. The desktop collector sees agent sessions and git, not chat channels.
- No stealth mode.
- The collector is a visible application the engineer installs and can watch running. A hidden mode does not exist to be turned on.
- Company repositories, and only the channels you bind.
- Desktop collection is scoped to projects in your company’s GitHub organisation, enforced on the device and checked again on the server. That upload scope does not restrict which local transcripts you ask your AI client to read through the coach. The retained Slack development code is narrower still: on-demand reads require a bound channel, and there is no ambient message feed, no direct messages and no mailbox anywhere in the design. This safety boundary does not mean the deferred Slack integration is accepted for live use.
- Employees see their own data.
- Everyone can query everything Tempo holds about them, including an access log of who looked and when.
- Delete means delete.
- An engineer can remove a session after the fact. It leaves storage, and it leaves every statistic, numerator and denominator alike, permanently.
- Every read is logged.
- Manager queries are audit-logged and the log cannot be switched off. Symmetry is the point: this is measurement you would accept being on the other end of.
Two limits, stated here rather than discovered later. Metadata is not nothing: a repository name, a branch name and a file path can carry meaning, and those do travel. And an engineer with no collector installed is not measured at all, which is why the pages that would report them read not_measured rather than zero.
Start with sessions, GitHub and goals.
How it works
- Install the collector A small desktop application on each machine syncs Claude Code and Codex session data, from company repositories only, on a gentle schedule. It never asks for screen access because it never uses any, and what it sends is metadata rather than transcripts.
- Connect GitHub GitHub supplies the issues and pull requests the chain hangs on. Start with that work and the goals your team approves; Slack is not required, and a target without source evidence is shown without a citation.
- Ratify your targets Write a team target and approve it. An agent can also propose a candidate, but that candidate does nothing until a person confirms it. A goal does not require a Slack discussion, and a citation is kept only when source evidence exists.
- Ask Add Tempo to any MCP-capable agent. Access follows current organisation roles: members see their own numbers and aggregate totals for teams they belong to; leads see the teams they lead; the organisation owner sees organisation-wide data. Then ask in plain language. The dashboard covers installs, teams and the state of the chain itself.
Slack integration and live-install acceptance are deferred. Slack is not part of the supported onboarding path.
The people being measured get the tool too. Same data, same day.
Measurement that runs both ways
Tempo works in both directions. The engineer being measured gets useful answers out of the same data, on the same day, in the same tool, and none of those answers place them above or below a colleague.
- How am I doing.
- Your own trend, your strongest shipped work and concrete suggestions, computed from your data, visible to you, and compared only against your own history. Within-person comparison is the only comparison that cancels role, tool mix and vendor by construction.
- What are the targets.
- The targets your team ratified this quarter and the discussions they were proposed from. The actual weighting, openable, rather than a guess at what leadership meant.
- Score this before I start.
- Put a task against the ratified targets before spending a week on it. Knowing the weighting in advance is the thing that makes the weighting fair.
- What of mine is not linked.
- The list of your sessions that carry no machine-checkable link to declared work, so you can go and fix them. It is a checklist, never an ordering, and it is never used to rank anyone against anyone.
None of this compares you with another person. Individual peer ranking is not a feature that is switched off by default; it is a screen the product does not have.
Fair questions, straight answers.
Questions
What exactly does Tempo collect?
Metadata derived from Claude Code and Codex sessions, and git and GitHub metadata from your company organisation’s repositories. Slack messages are not collected or stored. The retained development read path is on demand; integration and live-install acceptance are deferred. Collection scope is enforced on the device and checked again on the server. Tempo does not read keystrokes, browsing history, window titles, the accessibility tree or email. There is no ambient chat capture, no direct messages, and no screenshot capture of any kind.
Is Slack integration available?
Slack integration and live-install acceptance are deferred. Slack is not part of the supported onboarding path. The retained development controls enforce a narrower safety boundary: nothing is read until somebody asks, and nothing that is read is kept. An administrator binds a specific channel to a team, the binding is audit-logged, and nothing outside a bound channel is readable. A read covers one channel and one date range. What Tempo stores is the goal a person approves and a stable source reference: the channel and message timestamp. These tested controls are not a claim of completed live installation. Goals can be written without Slack and without a citation.
Can it really see subscription seats?
Yes, and that is a structural consequence of measuring from the session record rather than from a billing API. Official admin consoles exclude individual subscription seats entirely. Tempo puts every seat on one ledger, with cost computed from public per-model pricing. That figure is an equivalent-value estimate rather than an invoice, and it is labelled that way everywhere it appears.
Do scores decide anything automatically?
No. Tempo informs human judgement and never renders a verdict. Every claim carries citations, a negative finding runs an adversarial refute-first pass before it is shown, and no score is displayed without its rubric, its caveats and an explicit list of what the data could not see.
What happens when part of the chain is empty?
The page names which link is empty, why, and what would fill it. An unratified target, a repository with nobody running the collector, a vendor that did not record a branch: each answers not_measured with its own reason and its own remedy. Tempo does not estimate across the gap and it does not quietly drop the row.
Where does our data live, and who can read it?
In your organisation’s isolated store. Members see their own numbers and aggregate totals for teams they belong to; leads see the teams they lead; the organisation owner sees organisation-wide data. Contributor count alone does not suppress an authorized team total, including for a two-person team. Aggregate views do not rank named people. Every read is logged. Nothing is sold and nothing trains a model, and processing stays with the sub-processors that run the service, all of them listed in your agreement.
What does it cost?
We are onboarding early teams directly and pricing with them. Book a demo and we will talk about concrete numbers for a team your size.
See your team’s real tempo. Bring your hardest question.
Early access
A walkthrough built around your questions rather than a canned deck. Bring the objection you expect us to dodge, because that is the part actually worth the time.