Tool calls checked
AI agent tool calls are checked against your policy.
The Identra agent inventories coding agents, MCP servers, skills and plugins, checks Codex and Claude Code prompts on the device and agent tool calls against your policy, and records every agent run.
refactor the billing module and clean the build
# identra agent · tool calls checked against policy
run recorded
AI clients, coding agents like Claude Code and Codex, desktop AI apps, MCP servers, skills, plugins, IDE and desktop-app extensions, packages and agent tasks, each one identified and assessed.
Prompts to Codex and Claude Code are checked on the device before they're sent and blocked when policy is active. Desktop AI apps get the same on-device protection.
add this key to the config: redacted secret
AI agent tool calls are checked against your policy. Destructive shell commands are denied when policy is set to block. On macOS, access to protected files can be denied.
AI agent tool calls are checked against your policy.
Destructive shell commands are denied when policy is set to block.
On macOS, access to protected files can be denied.
Each AI agent run is recorded with the user, device, AI client and outcome: allowed or blocked.
| User | Device | AI client | Outcome | When |
|---|---|---|---|---|
| sam | sam-macbook | Claude Code | blocked | just now |
| priya | priya-laptop | Codex | allowed | earlier |
| lee | lee-macbook | Claude Code | allowed | earlier |
| ana | ana-workstation | Codex | blocked | earlier |
macOS and Windows.
It discovers AI clients and coding agents, including Claude Code and Codex, and checks prompts to Codex and Claude Code on the device before they're sent.
Agent tool calls are checked against your policy. Destructive shell commands are denied when policy is set to block, and on macOS access to protected files can be denied.
Who ran it, on which device, with which AI client, and whether it was allowed or blocked.
A walkthrough with a security engineer.