Everything it takes to run AI agents under control.
CAGIS.ai is one control plane spanning security, governance, agent management, cost, and intelligence. Every capability enforces on the endpoint, works offline, and rolls up to a single console and audit trail — so AI stays fast, useful, and accountable.
Threat detection that runs where the agent runs
A behavioral engine on every endpoint reads intent, not just strings — catching dangerous actions and multi-step attacks, and tokenizing secrets before they ever leave the machine.
60-rule behavioral catalog
Detection across recon, execution, impact, privilege escalation, persistence, integrity, credential access, defense-evasion, C2, lateral movement, and supply-chain — with strong macOS coverage, enforced on-device.
Multi-step chain detection
Correlates the actions in a session to catch attacks that span calls: secret-read → egress, disable-defenses → egress, and credential-theft → lateral movement — patterns no single rule would flag.
Shell-AST de-obfuscation
A POSIX shell tokenizer resolves quoting, ${IFS}, comments, and metacharacter tricks before evaluation, so an evasion can't smuggle a dangerous command past the rules.
Fails closed, offline-first
The gate is enforced on the endpoint and works fully offline. A crashed or missing hook never means allow. Online, it's defense-in-depth that can only tighten org policy, never loosen it.
PII & secret DLP
Detected secrets and PII are swapped for reversible vault tokens before the value reaches the model, your logs, or the wire — only {detector, count} metadata ever leaves the machine.
Reversible tokenization
Tokenization is lossless: the vault re-hydrates values only where they're authorized, so agents keep working while raw secrets never traverse an untrusted boundary.
Approve, deny, and prove it — fleet-wide
A native approval policy that rides on the agent's own prompts, every decision attributed and audited, and one place to author and push policy to every endpoint you run.
Native approval policy
Set allow, deny, or ask per action. "Ask" defers to the agent's own permission prompt — no custom dialog to learn — so governance rides on the workflow developers already use.
Every decision audited
Each allow, ask, or deny is recorded locally and on the server, attributed to a user and session, with the rule that fired — a defensible record for security and compliance reviews.
Per-user identity
Decisions and events carry user and session identity via SSO, so you can answer who ran what, where, and when — across the whole fleet, not just one laptop.
Central policy push
Author policy once in the multi-tenant console and push it to every endpoint over MDM/SSO. Rollouts are consistent and instant; no per-machine drift.
Compliance-ready evidence
Normalized events and tamper-resistant decision logs map to the controls you report against, turning day-to-day enforcement into audit evidence you can hand an assessor.
Policy that only tightens
Online enforcement is layered on top of the on-device baseline as defense-in-depth — it can add controls but can never weaken what the endpoint already enforces.
Every agent, every surface, one policy
From the terminal to hosted surfaces, CAGIS reaches the agents your teams actually use — with a single install, a live inventory, and the same governance everywhere.
Claude Code & Codex
A PreToolUse gate governs Claude Code natively and Codex through an adapter — the same policy, audit, and DLP across both, with a normalized event schema underneath.
Hosted surfaces via MCP gateway
Extend governance to claude.ai and Cowork through a remote MCP gateway, so agents outside the terminal answer to the same allow / ask / deny policy.
AI asset inventory
See the agents, plugins, and MCP servers running on every endpoint — the shadow-AI surface most orgs can't currently enumerate — in one fleet-wide inventory.
One-command deploy
Ships as a zero-dependency, Node-free compiled binary. Install the endpoint gate with a single command — curl … | sh — and it's governing from first run.
Deployed in one command
No runtime to provision, no agent SDK to bundle. The zero-dependency binary drops onto an endpoint and starts governing on first run.
Know what AI costs — and where to cut it
Token spend, metered per agent and per user, with budgets and optimization insight — so AI adoption comes with a bill you can attribute, forecast, and bring down.
Per-agent metering
Token usage and spend are metered per agent and per user, so cost is attributable instead of a single opaque line on an API bill.
Budgets & guardrails
Set budgets per team or agent and watch consumption against them, so runaway usage surfaces early instead of at month-end.
Optimization insight
Spot the agents and workflows driving spend and where an optional LLM proxy can route or right-size traffic to bring the bill down.
Analytics that turn enforcement into insight
A normalized event stream feeds adoption analytics and threat insight, so you can see how AI is used and how your risk posture is trending — from the same data that powers the gate.
Adoption analytics
See which teams and agents are actually using AI and how, so rollout decisions rest on real usage — not anecdote.
Threat insight
Trends across the rules that fire, the chains detected, and the actions blocked turn raw enforcement into a read on your live AI risk posture.
Normalized event stream
One consistent event schema across every surface makes analytics, detections, and audit line up instead of living in disconnected silos.
A defensible record of every AI action
Continuous monitoring at the boundary and a durable, attributed audit trail — the answer to who ran what, when, and why the gate decided the way it did.
Every tool call evaluated
Each agent action is assessed against policy at the boundary and recorded — continuous monitoring of what your AI is doing, not periodic sampling.
Attributed audit trail
A durable, tamper-resistant log of every decision — local and server-side — attributed to user and session, ready for incident review or an audit.
Defensible records
Normalized, queryable events give security teams a straight answer to who did what, when, and why the gate decided the way it did.
One path from endpoint to console
The endpoint gate makes the on-device decision; the platform API carries policy, audit, DLP, inventory, and metering; the dashboard turns it into evidence and insight.
Optional LLM gateway and MCP gateway extend the same control plane to hosted surfaces and proxied traffic.