AI coding agents run commands, read files, and reach the internet on behalf of a
developer — at machine speed, often without anyone watching. AgenShield puts a
boundary around them: it finds every agent, applies policy your security
team defines centrally to what each may run, read, and reach, and records
every decision.
Developers keep using Claude Code, Cursor, or Codex the way they already do.
The idea in one page
1
AgenShield finds the AI agents on the Mac
Every installed agent — Claude Code, Cursor, Codex CLI, Gemini CLI, and
many more — is detected automatically and governed as its own actor.
2
Policy arrives from your organization
The Mac receives a signed policy from the Frontegg Portal and applies it
locally — including while offline.
3
Every action is evaluated against that policy
AgenShield follows each agent’s execution tree — the agent, the tools
it runs, and their subprocesses — and checks everything they run, read,
and connect to. No per-agent setup, no new commands for developers.
4
You start by watching, not blocking
In monitor mode nothing is blocked; activity is simply recorded. That
evidence is what tells you which rules are worth enforcing.
5
You promote rules to enforcement one at a time
Turn on blocking for a specific rule once you have seen the real traffic —
never fleet-wide on day one.
Where to go next
How AgenShield works
The model behind the loop above: policy-governed agents, the execution tree, the three enforcement modes, and what AgenShield deliberately never touches. Read this before deploying.
Quickstart
Take one Mac from nothing to governed agents in about ten minutes.
What gets installed
Every component that lands on the Mac, what each is responsible for, where it lives, and how to confirm it is healthy.
Deploy to a fleet
Zero-touch rollout through Jamf, Kandji, Mosyle, JumpCloud, or Intune — no prompts on the endpoint.
Rollout playbook
The recommended path from first pilot Mac to enforced policy, and how to avoid breaking developer workflows on the way.
Working with your agents
For developers: what changes day to day, and what to do when something is blocked.
The AgenShield app
The menubar icon and the dashboard — status, activity, the policy in force, and one-click diagnostics.
The Frontegg Portal workflow, end to end
If you are the person setting AgenShield up, this is the order to do it in — all of it in the Frontegg Portal. Each page hands off to the next.Who each section is for
Good to know up front
- Policy is managed centrally. Developers cannot change policy or turn enforcement off locally — changes go through the Frontegg Portal. (The one local exception is the administrator-only emergency recovery below.)
- Protection survives being offline. The last policy the Mac received stays in force, and activity is recorded locally and uploaded when connectivity returns.
- It cannot lock you out of your Mac. The limits that protect your own account and macOS itself are built into the signed security extension and are not configurable — not by policy, not by an administrator, not by anyone with access to the device. If AgenShield ever misfires it heals itself automatically, and an administrator can always emergency-disable enforcement locally.
- macOS 14 or later, Apple silicon. Intel Macs are not supported yet. Intel and Linux support are in development. Windows has a one-line install today (see Install and uninstall), but enforcement is not yet at full parity with macOS — see Windows install warnings for two known limitations (an unsigned installer that triggers a Windows SmartScreen warning, and the command-line enrollment token method — not the install link or a Group Policy/Intune push — not completing on non-English Windows editions).