AgentKeeper documentation
Install AgentKeeper, set policy for AI coding agents, and investigate what those agents actually did on your fleet.
AgentKeeper watches what AI coding agents do on developer workstations. It evaluates each agent action against your policy before the action runs, and keeps an audit trail of everything that happened.
Pick the surface you are deploying. Each one installs independently.
Shield Agent
Hooks into Claude Code, Cursor, Codex, Gemini CLI, Windsurf, Copilot, and Antigravity. Monitors, warns, or blocks agent actions in real time.
MCP Gateway
Governs which MCP servers and tools agents can reach, and records every call that goes through.
Web Browser
Extends coverage to browser-based AI assistants across Chrome, Edge, and Firefox.
AI Agents SDK
Instruments agents you build yourself, using the same policy model and audit trail.
Start here
Connect one workstation
Install the plugin and authenticate. This takes a few minutes and does not require an MDM.
/plugin marketplace add rad-security/claude-code-plugin
/plugin install agentkeeper
/agentkeeper:connect
Restart your agent afterward so the hooks load at startup. Other IDEs use the installer described in Installation.
Watch it decide something
Run an action your policy should catch. The decision appears in the dashboard with the rule that produced it.
See Policy outcomes for what Monitor, Warn, and Block mean on each surface.
Set policy for the fleet
Base Policy applies everywhere. Policy Profiles narrow it by group.
See Runtime Shield for the policy model and Detections for the detector catalog.
Roll out
Deploy through Intune, Jamf, Kandji, or Iru. See Network requirements before you start, so egress and TLS inspection are settled up front.