> ## Documentation Index
> Fetch the complete documentation index at: https://docs.agen.co/llms.txt
> Use this file to discover all available pages before exploring further.

# AgenShield

> Endpoint security for AI coding agents on macOS — see what your agents actually do, then govern it with centrally managed policy, without changing how developers work.

<img src="https://mintcdn.com/agenshield/ZSVv7ExfJBS5KzGd/images/page-heroes/index.png?fit=max&auto=format&n=ZSVv7ExfJBS5KzGd&q=85&s=90308d96bbdf72830d7281a2032df073" alt="AgenShield Overview cover — one boundary between your agents and everything they touch." noZoom width="1920" height="880" data-path="images/page-heroes/index.png" />

AI coding agents run commands, read files, and reach the internet on behalf of a
developer — at machine speed, often without anyone watching. AgenShield puts a
boundary around them: it **finds every agent**, applies **policy your security
team defines centrally** to what each may run, read, and reach, and **records
every decision**.

Developers keep using Claude Code, Cursor, or Codex the way they already do.

## The idea in one page

<Steps>
  <Step title="AgenShield finds the AI agents on the Mac">
    Every installed agent — Claude Code, Cursor, Codex CLI, Gemini CLI, and
    many more — is detected automatically and governed as its own actor.
  </Step>

  <Step title="Policy arrives from your organization">
    The Mac receives a signed policy from the Frontegg Portal and applies it
    locally — including while offline.
  </Step>

  <Step title="Every action is evaluated against that policy">
    AgenShield follows each agent's **execution tree** — the agent, the tools
    it runs, and their subprocesses — and checks everything they run, read,
    and connect to. No per-agent setup, no new commands for developers.
  </Step>

  <Step title="You start by watching, not blocking">
    In **monitor** mode nothing is blocked; activity is simply recorded. That
    evidence is what tells you which rules are worth enforcing.
  </Step>

  <Step title="You promote rules to enforcement one at a time">
    Turn on blocking for a specific rule once you have seen the real traffic —
    never fleet-wide on day one.
  </Step>
</Steps>

That loop — **observe, decide, enforce, repeat** — is the whole product.

## Where to go next

<Columns cols={2}>
  <Card title="How AgenShield works" icon="lightbulb" href="./how-it-works.mdx">
    The model behind the loop above: policy-governed agents, the execution tree, the three enforcement modes, and what AgenShield deliberately never touches. Read this before deploying.
  </Card>

  <Card title="Quickstart" icon="rocket" href="./getting-started/quickstart.md">
    Take one Mac from nothing to governed agents in about ten minutes.
  </Card>

  <Card title="What gets installed" icon="boxes" href="./components.mdx">
    Every component that lands on the Mac, what each is responsible for, where it lives, and how to confirm it is healthy.
  </Card>

  <Card title="Deploy to a fleet" icon="building-2" href="./deployment/mdm/overview.mdx">
    Zero-touch rollout through Jamf, Kandji, Mosyle, JumpCloud, or Intune — no prompts on the endpoint.
  </Card>

  <Card title="Rollout playbook" icon="map" href="./deployment/rollout-playbook.mdx">
    The recommended path from first pilot Mac to enforced policy, and how to avoid breaking developer workflows on the way.
  </Card>

  <Card title="Working with your agents" icon="terminal" href="./using/working-with-agents.mdx">
    For developers: what changes day to day, and what to do when something is blocked.
  </Card>

  <Card title="The AgenShield app" icon="app-window" href="./using/the-app.mdx">
    The menubar icon and the dashboard — status, activity, the policy in force, and one-click diagnostics.
  </Card>
</Columns>

## The Frontegg Portal workflow, end to end

If you are the person setting AgenShield up, this is the order to do it in —
all of it in the [Frontegg Portal](https://portal.frontegg.com). Each page
hands off to the next.

| # | Step                                                              | You end up with                                              |
| - | ----------------------------------------------------------------- | ------------------------------------------------------------ |
| 1 | [Create an install campaign](./deployment/campaigns.mdx)          | An enrollment token and ready-made deployment artifacts      |
| 2 | [Enroll devices](./deployment/mdm/overview.mdx)                   | Macs reporting in, with no prompts on a managed fleet        |
| 3 | [Read the fleet](./deployment/devices.mdx)                        | Health, coverage, and which policy revision is actually live |
| 4 | [Watch telemetry](./configuration/telemetry.mdx)                  | Evidence of what your agents really do                       |
| 5 | [Write rules](./configuration/policies.mdx)                       | Narrow, agent-scoped policy built on that evidence           |
| 6 | [Set the enforcement mode](./configuration/enforcement-modes.mdx) | Monitor first, then one rule at a time                       |
| 7 | [Govern agent resources](./configuration/agent-resources.mdx)     | Reviewed skills and connectors instead of whatever appeared  |

## Who each section is for

| You are…                              | Start with                                                                                                         |
| ------------------------------------- | ------------------------------------------------------------------------------------------------------------------ |
| Evaluating AgenShield                 | [How AgenShield works](./how-it-works.mdx), then [Privacy and data handling](./configuration/privacy-and-data.mdx) |
| Rolling it out to a fleet             | [Install campaigns](./deployment/campaigns.mdx), then [MDM deployment](./deployment/mdm/overview.mdx)              |
| Planning the rollout sequence         | [Rollout playbook](./deployment/rollout-playbook.mdx)                                                              |
| Setting up your own Mac               | [Quickstart](./getting-started/quickstart.md)                                                                      |
| A developer whose agents are governed | [Working with your agents](./using/working-with-agents.mdx)                                                        |
| Supporting someone else               | [Common issues](./troubleshoot/common-issues.mdx)                                                                  |

## Good to know up front

* **Policy is managed centrally.** Developers cannot change policy or turn
  enforcement off locally — changes go through the
  [Frontegg Portal](https://portal.frontegg.com). (The one local exception is
  the administrator-only emergency recovery below.)
* **Protection survives being offline.** The last policy the Mac received stays
  in force, and activity is recorded locally and uploaded when connectivity
  returns.
* **It cannot lock you out of your Mac.** The limits that protect your own
  account and macOS itself are built into the signed security extension and are
  not configurable — not by policy, not by an administrator, not by anyone with
  access to the device. If AgenShield ever misfires it heals itself
  automatically, and an administrator can always
  [emergency-disable enforcement locally](./how-it-works.mdx#it-cannot-lock-you-out).
* **macOS 14 or later, Apple silicon.** Intel Macs are not supported yet. Intel
  and Linux support are in development. Windows has a one-line install today
  (see [Install and uninstall](./getting-started/install-and-uninstall.md)), but
  enforcement is not yet at full parity with macOS — see
  [Windows install warnings](./troubleshoot/windows-install-warnings.mdx) for two
  known limitations (an unsigned installer that triggers a Windows SmartScreen
  warning, and the command-line enrollment token method — not the install link
  or a Group Policy/Intune push — not completing on non-English Windows
  editions).
