AgentKeeper documentation

Install AgentKeeper, set policy for AI coding agents, and investigate what those agents actually did on your fleet.

AgentKeeper watches what AI coding agents do on developer workstations. It evaluates each agent action against your policy before the action runs, and keeps an audit trail of everything that happened.

Pick the surface you are deploying. Each one installs independently.

Start here

Connect one workstation

Install the plugin and authenticate. This takes a few minutes and does not require an MDM.

/plugin marketplace add rad-security/claude-code-plugin
/plugin install agentkeeper
/agentkeeper:connect

Restart your agent afterward so the hooks load at startup. Other IDEs use the installer described in Installation.

Watch it decide something

Run an action your policy should catch. The decision appears in the dashboard with the rule that produced it.

See Policy outcomes for what Monitor, Warn, and Block mean on each surface.

Set policy for the fleet

Base Policy applies everywhere. Policy Profiles narrow it by group.

See Runtime Shield for the policy model and Detections for the detector catalog.

Roll out

Deploy through Intune, Jamf, Kandji, or Iru. See Network requirements before you start, so egress and TLS inspection are settled up front.

Common questions