Govern every move your AI agents make.
CAGIS.ai is the enterprise control plane for AI coding agents. Every risky action is evaluated on the endpoint against your policy, secrets are tokenized before they leak, and every decision is audited — where AI intelligence meets governance, security, and cost control.
How CAGIS.ai works
Sixty seconds: the gate intercepts every agent action, routes what matters to a human, tokenizes secrets before they leak, and rolls the whole fleet into one console.
60 seconds · sound on for the full walkthrough (captions included)
Your teams gave AI agents a terminal. Who's watching?
Coding agents now run shell commands, read files, hit the network, and call tools — at machine speed, on every laptop. One prompt-injection or one careless command can exfiltrate a secret, wipe a disk, or phone home, and most orgs have no policy, no audit trail, and no idea how much it costs.
Five disciplines, one control plane
Per-agent token & spend metering, budgets, and optimization.
Govern Claude Code, Codex, and hosted AI surfaces.
Native approval policy — allow, ask, or deny — fully audited.
Threat detection, DLP, and inventory without the friction.
60-rule catalog, chains, shell-AST, secret tokenization.
Containment, not restriction
Enterprise guardrails that keep agents fast and useful — while making sure they can't read a secret, wipe a disk, or exfiltrate data without you knowing.
Behavioral threat detection
A 60-rule catalog across recon, execution, credential access, defense-evasion, C2, lateral movement, and supply-chain — enforced on-device, even offline.
Multi-step chain detection
Correlates a session's actions to catch attacks that span calls: read a secret → exfiltrate it, disable defenses → egress, steal creds → move laterally.
Shell-AST de-obfuscation
A linear POSIX tokenizer resolves quoting, ${IFS}, comments and metacharacter tricks, so evasions can't hide a dangerous action.
PII & secret DLP
Secrets are swapped for reversible vault tokens before the model, your logs, or the wire ever see them — only detector metadata leaves the machine.
Native approval policy
Allow, deny, or defer to the agent's own permission prompt. No custom dialogs. The gate fails closed — a crashed hook never means allow.
Cost & inventory
Per-agent spend, budgets, adoption analytics, and a fleet-wide inventory of the AI assets on every endpoint.
Priced on the risk you remove
CAGIS surfaces the value it delivers — leaks prevented, incidents caught, spend saved — and prices on the protection you get, not the number of people who log in.
Everywhere your agents run
From the terminal to hosted surfaces — governed by one policy, one audit trail, one console.
Where the URL + token go: the installer prompts for your CAGIS server URL (e.g. https://cagisai.aiatscale.dev/api) and your agent token (Dashboard → My Agent). To skip the prompts (paste / MDM), pass them: …/install.sh | sh -s -- --url https://…/api --token cagis_…. Then restart Claude Code — risky actions are now governed.
Prefer the Claude Code plugin? /plugin marketplace add dinesh2648/CAGIS-ai → /plugin install cagis@cagis → cagis install.