


Permit Coding Agents Gateway
Every call from Cursor, Claude Code, and Codex: intent interrogated, behavior watched, decided by policy. Default-deny, governed through your IGA, audited to your SIEM.
Deployed by MDM · Sees what EDR can't · Governed by IGA
gateway · live decisions
Enforcingcopilot-agent $ GET internal-api.acme.dev/schemas
policy · scoped grant via delegation
claude-code $ read ~/.aws/credentials
policy · default-deny, no matching grant
codex $ POST paste-bin.cc/x91f · payload: env vars
guardian · exfiltration pattern detected
cursor $ POST registry.npmjs.org /publish
policy · high-risk path → human approval
claude-code $ GET api.github.com/repos/acme/api
policy · destination on allowlist
Interrogation asks · Guardians watch · Policy decides
A process-level proxy on the endpoint—no reliance on the agent vendor's cooperation, no per-tool settings silos.
Coding agents aren't shadow IT—you approved them. They hold shell access, credentials, and unrestricted outbound reach. And every control in your endpoint stack keys on an artifact they never produce.

It's already being exploited
Aug 2025 · Supply Chain
A malicious npm postinstall invoked locally installed Claude Code, Gemini CLI, and Amazon Q with unsafe flags to hunt credentials, SSH keys, and wallets.
Source: Snyk →
May 2026 · Supply Chain
A payload built specifically to harvest AI coding agent configuration—hunting ~/.claude/settings.json on developer machines.
Source: StepSecurity →
Jun 2026 · EDR Telemetry
Sophos telemetry shows Claude Code, Cursor, and Codex routinely tripping endpoint rules written for human intruders—during ordinary work. Benign and hijacked agents look identical.
Source: The Hacker News →
2026 · Prompt Injection
Prompt-injection-to-exfiltration chains demonstrated against Claude Code, Gemini CLI, and Copilot Agent. CSA treats agentic CI/CD injection as an architectural risk.
Source: Cloud Security Alliance →
The industry's answer is AIDR—and the incumbents validated it with their checkbooks. But what ships today watches prompts and guesses.
Governing coding agents takes enforcement, not another alert
Three layers ladder from probabilistic to deterministic. Every layer can raise a flag; only policy grants access. Guardrails are probabilistic. Policy is a guarantee.

Verifies the intent behind each agentic call and detects drift toward dangerous behavior—catching prompt injection where it manifests: at the action, not the prompt.
Keep watching after access is granted. Runtime monitoring across the session catches behavior that only becomes suspicious in sequence—escalation, odd destinations, workflow divergence.
The final call is always deterministic policy, powered by the Permit platform: default-deny baseline, explicit allowlists, trust levels, human-in-the-loop, Rego/ABAC—at sub-10ms decision speed.
Incidents that never happen instead of alerts that need triage—the “preemptive” in preemptive AIDR.
Detect
Outcome: Distinguish a benign agent from a hijacked one—the ability EDR structurally lacks.
Prevent
Outcome: The control model every CISO already trusts, applied to the one process class nothing else governs.
Govern
Outcome: Least privilege and audit-readiness for the agentic workforce—extending the IAM investment you already made.
A user-space proxy scoped to coding agent processes—pushed through the MDM and software-distribution tooling you already run. It governs agent traffic, not the whole device.
Deploys like MDM
Admins push the gateway to managed endpoints with existing distribution tooling. It sits at the process level of Cursor, Claude Code, Codex, and other agents—no per-developer setup, no vendor cooperation required.
Firewall logic, agent scope
All outbound blocked, explicit allowlist for approved destinations. Then refine: trust levels for low-risk paths, human-in-the-loop approvals on dangerous ones, Rego/ABAC for the finest resolution.
Governs like IAM
Agent identities provisioned into your IGA, permissions expressed as ReBAC relationships to the humans who delegate them. Every decision—human, agent, action, resource, outcome—audited to your SIEM.

One Brain, Many Enforcement Points
The same agent identity graph and policy fabric as the Permit MCP Gateway—one chain of control that now starts at the developer's machine and runs to the database row.
Same identities, same policies, same audit chain. Not another silo—the second instantiation of an architecture your organization may already run.
The Gateway is built on the Permit platform these teams already trust—years of authorization infrastructure underneath, not a 2026 vendor deck.
<10ms
PDP policy decisions—enforcement that keeps pace with agent speed
100M+
identities served at sub-50ms by the same policy engine
SOC 2
Type II—plus HIPAA, GDPR, and CCPA compliance
Right category—different object. Their AIDR instruments AI usage across browsers and apps and classifies prompts. Coding agents are sanctioned processes performing non-installable actions on the endpoint. Governing that takes process-level enforcement that ends in deterministic policy. In a Falcon shop, we coexist: their telemetry, our enforcement.
Sophos’ own telemetry shows today’s EDR can’t tell a working agent from an attack—the behaviors are identical. Structurally, EDR’s unit of analysis is the process and the syscall; what makes an agent dangerous is its decision, which lives in intent and context EDR never sees. You need enforcement before a roadmap arrives.
Keep them—they’re seatbelts. But they’re per-vendor config files: no identity, no interrogation, no runtime response, no coverage for the next agent. The Gateway gives you one policy fabric across all coding agents tied to your IGA—and verifies those native settings stay present and compliant, turning them into audited controls.
The design assumes they shouldn’t have to notice. The allowlist makes normal work invisible; trust levels let low-risk paths run frictionless; human-in-the-loop appears only on dangerous ones. This is the control that lets you approve coding agents broadly instead of restricting them narrowly.
It’s an admin-installed, user-space proxy scoped to coding agent processes—pushed through the MDM and software-distribution tooling you already run. It governs agent traffic, not the whole device, which keeps both the performance footprint and the developer-privacy conversation small.
It would be, if it made the decision. It doesn’t. The layers ladder: interrogation and guardian agents raise signals; only the deterministic policy layer grants access. Probabilistic defenses, deterministic decisions.
Let developers move at AI speed. Keep the blast radius at policy speed.
Or explore the agent.security platform →