See Straza in action.
Run a local server, enroll a user and see a policy deny a command, then explore the setup that fits your team.
Recommended first path
Try it on one machine
No external services required. The tutorial uses a POSIX shell. Claude Code is optional.
- Install the three binaries
Server, admin CLI, and client.
- Run your first session
See a policy allow and deny.
- Understand the result
Connect identity, policy, and audit.
Other places to start
Connect an MCP server
Register a server, choose its credentials, and give a role access to tools.
Explore an enterprise setup
Run the demo stack with identity services and working agents.
Every page in this section
- Install puts the three Straza binaries on your PATH and verifies where they came from.
- Your first governed session starts a local server, enrolls a user and shows a policy allow and deny example commands.
- What just happened explains the user, the session, the policy and the audit record behind that first run.
- The demo stack runs Straza behind midPoint and Keycloak with working agents, and then keeps that stack running for a team.
- Run it on Kubernetes reaches a first deny on a throwaway kind cluster through the Helm chart.