Govern agents
Put one agent under Straza policy, harness by harness.
-
Claude Code puts Claude Code under Straza policy on one machine and confirms the first governed call.
-
Codex CLI puts Codex CLI under Straza policy on one machine.
-
Gemini CLI puts Gemini CLI under Straza policy on one machine.
-
Python agents governs a Python agent with the Straza agent kit, so every tool call passes through policy.
-
Any MCP client points an MCP client at the Straza gateway, so its tool calls are governed without a harness hook.
-
Hookless processes runs a process that has no hook surface inside the Straza sandbox, so its actions still meet policy.
-
Headless agents enrolls an AI agent with no person at the keyboard, with a key it holds, so it checks in without a browser.
-
Enroll a machine enrolls a machine once, before any harness page.
-
What the agent reads back shows the deny reasons, the pending answers and the approval tools an agent sees.
-
Knowledge packs says what a pack holds and how an agent gets it.