CONTROL AGENT ACTIONS

Govern MCP servers, skills and plugins

You approved the AI agent. Do you know what its added tools can reach? Identra discovers MCP servers, skills and plugins on macOS and Windows endpoints, checks agent tool calls against policy and records each run with the person behind it.

WORKS INEndpoint
MCP serversCOVERED
  1. See the additions around each agent01
  2. Apply policy to agent tool calls02
  3. Deny destructive shell commands03
  4. Protect files on macOS04
  5. Know who ran what05
ONE IDENTITY · ONE TIMELINEEndpoint
01What goes wrong today

The risk is already in use.

What security teams run into with MCP servers today, before a control is in place.

  • 01

    Approval is only the start

    An approved coding agent can gain new capabilities through MCP servers, skills and plugins. The original review may no longer reflect what the agent can do.

  • 02

    Additions escape the inventory

    Employees add tools as their work changes. Security teams can lose track of which servers, skills and plugins are present.

  • 03

    Useful tools can cause damage

    An agent with shell or file access can turn a mistaken instruction into a destructive action. Written usage rules alone do not stop that action.

  • 04

    Accountability takes too long

    When an agent does something unexpected, security needs to know who ran it, on which device and what happened.

02What Identra does

What changes with Identra.

Covered by Identra on macOS and Windows, tied to one identity and one timeline.

Identra on macOS and WindowsSee Identra on the endpoint
  • 01

    See the additions around each agent

    Identra discovers MCP servers, skills and plugins alongside coding agents and desktop AI apps on macOS and Windows. Bring these additions into your AI inventory.

  • 02

    Apply policy to agent tool calls

    Identra checks AI agent tool calls against policy. Put defined boundaries around agent actions.

  • 03

    Deny destructive shell commands

    Identra denies destructive shell commands when policy is set to block. A mistaken agent instruction does not become a damaging command.

  • 04

    Protect files on macOS

    On macOS, Identra can deny AI agent access to protected files. Keep sensitive files out of an agent's reach.

  • 05

    Know who ran what

    Identra records AI agent runs with the user, device, AI client and allowed or blocked outcome. Give investigations a clear account of agent activity.

03Before and after

A coding agent gains more tools

The same moment, played twice. Once without Identra, once with it.

WITHOUT IDENTRA

EXPOSED
  1. A developer adds an MCP server and a skill to a coding workflow on a Mac.

  2. Security's inventory lists the coding agent but misses the new additions.

  3. During a cleanup task, the agent attempts a destructive shell command.

  4. Security must piece together who ran the agent and what happened.

WITH IDENTRA

CONTAINED
  1. Identra discovers the coding agent, MCP server and skill on the developer's Mac.

  2. With policy set to block, Identra denies the destructive shell command.

  3. Protected-file controls on macOS can also deny the agent access to protected files.

  4. The agent run is recorded with the developer, device, AI client and blocked outcome.

04How it works

Four steps. One timeline.

  1. 01

    See

    Bring MCP servers, skills and plugins into your endpoint AI inventory.

  2. 02

    Govern

    Have AI agent tool calls checked against your policy.

  3. 03

    Enforce

    Deny destructive shell commands when blocking policy is active and protect file access on macOS.

  4. 04

    Record

    Review agent runs with the user, device, AI client and allowed or blocked outcome.

QUESTIONS

What buyers ask us about MCP servers.

Does discovering an MCP server mean all its actions are blocked?

Discovery gives you an inventory of MCP servers, skills and plugins. Enforcement applies to specific actions: AI agent tool calls are checked against policy, destructive shell commands can be denied, and protected-file access can be denied on macOS.

What do we deploy?

Deploy the Identra endpoint agent on macOS and Windows to discover coding agents, desktop AI apps, MCP servers, skills and plugins. Learn more about the endpoint platform.

How does Identra handle prompt privacy?

Prompts to Codex and Claude Code are checked on the device before they are sent, and blocked when policy is active. Desktop AI composers get the same on-device checks.

Can employees keep using their coding agents?

Identra checks agent tool calls against policy and denies destructive shell commands when policy is set to block. This gives you specific controls for agent actions within existing coding workflows.

Is coverage the same on macOS and Windows?

The endpoint agent runs on macOS and Windows. Protected-file access denial is a macOS capability.

What can we review after an agent run?

Identra records the user, device, AI client and allowed or blocked outcome for AI agent runs. Where the person is known, endpoint activity joins browser and provider activity in one identity timeline.

SEE IT IN YOUR ENVIRONMENT

See Identra handle MCP servers.

A walkthrough with a security engineer.