Spend you can't see
Everyone is on their own subscription. Nobody can tell you who is burning what, on which model, or whether it produced anything.
Your developers already use Claude Code. shipsuit makes it cheaper and consistent — every prompt analysed against your standards, every merge reviewed against your rules, and a fraction of the tokens. No source code ever leaves their machines.
Everyone is on their own subscription. Nobody can tell you who is burning what, on which model, or whether it produced anything.
Your rules exist in senior engineers' heads and get applied at PR time — after the code is written, if the right person is looking.
Every developer explains the architecture to Claude again. Different explanations, different answers, every day.
Every prompt your developers type is classified on their own machine before Claude sees it. When it touches something your company has a rule about, that rule rides along automatically. The developer types normally; Claude answers to your standards.
Gates, rule scans and git state run as local scripts. The model reads compact findings, never whole diffs. Measured 66–86% less context than hand-rolled.
The rules your team argues about — money, transactions, what may touch production — encoded once, served per run. On a developer's machine they're advice. In CI the scan exits non-zero, so a blocker fails the build.
Every developer's Claude starts from the same generated repo guide. Nobody re-explains the architecture. New hires inherit it from git on day one.
Pre-merge review, quality gates and a staging-aware PR flow arrive as commands. Add your own as data — no release, no redeploy, nothing for developers to do.
Scans run locally. We receive counts, durations and versions — enforced by schema, not by promise. No source, no paths, no prompt text.
Tokens, cost, sessions, active time and accepted edits — per developer, per team, over 24 hours, 7 days or 30. Even when everyone is on their own subscription.
Your house rules and review checklist become a served ruleset. It never lands on a developer's disk.
The plugin installs itself and the settings are committed. Every clone and every new hire inherits it from git.
Gates, rule scan and a judgment review before code reaches production. Wire the same scan into CI and a blocker stops the build — plus a usage picture leadership can act on.
Not a policy — a property of the design. Every check runs locally, and the only thing that crosses the network is a fixed set of counters.
The ingest boundary is an allowlist. A field we haven't named cannot be stored, however the payload changes.
Prompts are classified on the developer's own machine. Only the category label is ever recorded — never the words.
Counts, durations, model names, versions. No source, no file paths, no branch names, no free text of any kind.
Every query is scoped by company at a single choke point, and a test suite that must stay green proves one customer can never see another.
Each person gets their own credential, individually revocable. Offboarding someone kills their access without touching anyone else.
Licensed rulesets are served per run and never written to a developer's disk — they leave with the subscription.
The question is what you get back. Onboard one repo and compare a week of usage against the week before.