IDENTRA AGENTFor macOS and Windows

Your laptops run AI agents. Make them answer to policy.

The Identra agent inventories coding agents, MCP servers, skills and plugins, checks Codex and Claude Code prompts on the device and agent tool calls against your policy, and records every agent run.

See an agent run
POLICY
claude-code · ~/payments-service

refactor the billing module and clean the build

# identra agent · tool calls checked against policy

  1. readsrc/billing/*ALLOWED
  2. editsrc/billing/invoice.tsALLOWED
  3. shellrm -rf ./DENIED · destructive command
  4. read~/.ssh/DENIED · protected fileon macOS

run recorded

RUN RECORDjust now
USER
sam
DEVICE
sam-macbook
AI CLIENT
Claude Code
OUTCOME
blocked

§ 01AI inventory

Coding agents, MCP, skills. One inventory.

AI clients, coding agents like Claude Code and Codex, desktop AI apps, MCP servers, skills, plugins, IDE and desktop-app extensions, packages and agent tasks, each one identified and assessed.

AI INVENTORY
  • sam-macbookDEVICE
    • Coding agents
      • Claude CodeCODING AGENT
      • CodexCODING AGENT
    • MCP servers
      • filesystemMCP
      • databaseMCP
      • issue trackerMCP
Flagged by Identra.
§ 02Prompts

Coding-agent prompts checked before they’re sent.

Prompts to Codex and Claude Code are checked on the device before they're sent and blocked when policy is active. Desktop AI apps get the same on-device protection.

CODEX · PROMPT

add this key to the config: redacted secret

BLOCKED BY POLICYChecked on this device.
§ 03Tool calls

Agent tool calls answer to policy.

AI agent tool calls are checked against your policy. Destructive shell commands are denied when policy is set to block. On macOS, access to protected files can be denied.

POLICY

Tool calls checked

AI agent tool calls are checked against your policy.

editsrc/billing/invoice.tsALLOWED
IN BLOCK MODE

Destructive commands denied

Destructive shell commands are denied when policy is set to block.

shellrm -rf ./DENIED
ON macOS

Protected files

On macOS, access to protected files can be denied.

read~/.ssh/DENIED
§ 04Every run on the record

Every agent run. On the record.

Each AI agent run is recorded with the user, device, AI client and outcome: allowed or blocked.

UserDeviceAI clientOutcomeWhen
samsam-macbookClaude Codeblockedjust now
priyapriya-laptopCodexallowedearlier
leelee-macbookClaude Codeallowedearlier
anaana-workstationCodexblockedearlier
RUN RECORDEDsam on sam-macbook
ONE IDENTITY

Agent runs land on the person’s timeline, next to their browser and cloud activity.

QUESTIONS

The Identra agent, answered.

Which operating systems does the Identra agent support?

macOS and Windows.

Which coding agents does it cover?

It discovers AI clients and coding agents, including Claude Code and Codex, and checks prompts to Codex and Claude Code on the device before they're sent.

Does it block agents?

Agent tool calls are checked against your policy. Destructive shell commands are denied when policy is set to block, and on macOS access to protected files can be denied.

What is recorded for each agent run?

Who ran it, on which device, with which AI client, and whether it was allowed or blocked.

BOOK A WALKTHROUGH

Put policy between AI agents and your laptops.

A walkthrough with a security engineer.