# AgentKeeper Documentation ## English - [AgentKeeper documentation](https://docs.agentkeeper.dev/index.md): Connect an AI-agent surface, apply policy at the action boundary it exposes, and verify the resulting evidence in AgentKeeper. - [Choose your rollout](https://docs.agentkeeper.dev/start-here/choose-your-rollout.md): Pick between a single workstation, a team, or an MDM-managed fleet, and see what each path requires. - [Evaluate one workstation](https://docs.agentkeeper.dev/start-here/installation.md): Connect Claude Code on one workstation and prove live Activity evidence plus a controlled pre-execution block before expanding the rollout. - [Connect Claude Code](https://docs.agentkeeper.dev/connect/agents/claude-code.md): Install the AgentKeeper plugin in Claude Code, prove that its hooks loaded, and validate one allowed and one blocked action before rollout. - [Cursor Setup](https://docs.agentkeeper.dev/connect/agents/cursor-setup.md): AgentKeeper hooks into Cursor's tool use lifecycle so teams can enable Composer or Agent Chat with policy checks around shell commands, MCP tool calls, file access, prompts, and Cursor's generic... - [Windsurf / Devin Desktop Setup](https://docs.agentkeeper.dev/connect/agents/windsurf-setup.md): AgentKeeper integrates with both hook systems shipped by the current product: Cascade hooks for the Editor experience, and Devin lifecycle hooks for Devin CLI and the Devin Local agent inside... - [GitHub Copilot Setup](https://docs.agentkeeper.dev/connect/agents/copilot-setup.md): AgentKeeper integrates with GitHub Copilot through the official Copilot hooks reference for Copilot CLI and Copilot cloud agent, plus VS Code-compatible payloads where the installed Copilot... - [Codex Setup](https://docs.agentkeeper.dev/connect/agents/codex-setup.md): AgentKeeper integrates with Codex through the official Codex hook system. The public installer uses the current hooks feature flag and wires the six documented lifecycle events that matter for... - [Gemini CLI Setup](https://docs.agentkeeper.dev/connect/agents/gemini-setup.md): AgentKeeper integrates with Gemini CLI through command hooks. The Gemini adapter converts hook payloads into AgentKeeper's canonical Bash, Read, Write, Edit, Grep, Glob, WebFetch, and MCP skill... - [Antigravity CLI Setup](https://docs.agentkeeper.dev/connect/agents/antigravity-setup.md): AgentKeeper integrates with Antigravity CLI and Antigravity Desktop through the shared Antigravity hook system. There is no Antigravity browser-extension component in this integration. - [Claude Chat Setup](https://docs.agentkeeper.dev/connect/agents/claude-chat-setup.md): Claude Chat runs inside the Claude Desktop app. AgentKeeper protects Chat MCP tool calls by routing Claude Desktop through AgentKeeper MCP Gateway, then evaluating each tool call against policy... - [Connect Claude Cowork](https://docs.agentkeeper.dev/connect/agents/cowork.md): Choose the correct AgentKeeper evidence and enforcement path for remote Cowork, local Cowork, plugins, MCP Gateway, and telemetry. - [Configuration](https://docs.agentkeeper.dev/connect/team/configuration.md): AgentKeeper configuration depends on which agent surface you are securing. Claude Code can load hooks from the AgentKeeper plugin, user/project settings.json, or managed settings. The recommended... - [Deployment overview](https://docs.agentkeeper.dev/connect/team/team-deployment.md): Use this page to choose the right rollout path before you touch Jamf, Iru/Kandji, Intune, Linux software distribution, Claude Code, or Claude Desktop Cowork. For managed endpoint runtime installs,... - [GitHub Integration](https://docs.agentkeeper.dev/connect/team/github-integration.md): Connect your GitHub repositories to AgentKeeper and auto-deploy Claude Code policy hooks to every repo your team works in. One click to connect, one PR to cover the repo. Every developer who... - [GitHub Repo Hooks](https://docs.agentkeeper.dev/connect/team/github-repo-hooks.md): Deploy AgentKeeper hooks via your Git repository. Commit a .claude/settings.json once, every developer who clones the repo gets automatic Claude Code policy enforcement for that repository. - [Enterprise install](https://docs.agentkeeper.dev/connect/fleet/enterprise-install.md): Use these guides to install AgentKeeper Runtime on managed Windows, macOS, and Linux devices. - [Enrollment tokens](https://docs.agentkeeper.dev/connect/fleet/enrollment-tokens.md): Create, scope, and revoke the tokens your MDM uses to enroll workstations without a developer signing in. - [Download artifacts](https://docs.agentkeeper.dev/connect/fleet/artifacts.md): Pin one AgentKeeper Runtime version before assigning it through MDM. Keep metadata and checksums with the deployment record. - [Deploy the universal macOS installer](https://docs.agentkeeper.dev/connect/fleet/macos/macos.md): AgentKeeper uses one universal signed PKG on Apple silicon and Intel Macs. Use the same PKG with Jamf, Iru/Kandji, or Intune. You do not need an IDE menu, a companion installer, or a fleet API... - [Jamf deployment](https://docs.agentkeeper.dev/connect/fleet/macos/jamf.md): Jamf deploys the same universal AgentKeeper PKG used by every macOS MDM. There is no Jamf-specific installer, companion install script, or IDE menu. - [Intune deployment](https://docs.agentkeeper.dev/connect/fleet/macos/intune.md): macOS uses the universal signed PKG. Windows uses the promoted IntuneWin from the production feed. A signed workflow candidate remains validation-only until the release evidence gates pass and a... - [Iru deployment](https://docs.agentkeeper.dev/connect/fleet/macos/iru.md): Iru/Kandji deploys the same universal AgentKeeper PKG used by Jamf and Intune. The PKG reconciles seven local IDE/CLI surfaces; Cowork and MCP Gateway remain separate deployments. - [Windows enterprise install](https://docs.agentkeeper.dev/connect/fleet/windows/windows.md): Install AgentKeeper Runtime on managed Windows devices. The Windows package installs one runtime service, one per-device credential flow, the MCP gateway binary, and the supported IDE hook helpers. - [Linux RPM enterprise install (Beta)](https://docs.agentkeeper.dev/connect/fleet/linux/linux.md): Install AgentKeeper Runtime on managed x86_64 RHEL 8/9 and Rocky Linux 8/9 workstations. The signed RPM includes runtime policy, AI-agent discovery, reconciliation, and MCP Gateway. - [AWS WorkSpaces deployment (Beta)](https://docs.agentkeeper.dev/connect/fleet/linux/aws-vdi.md): Deploy the same signed AgentKeeper RPM to persistent WorkSpaces Personal and pooled or ephemeral sessions. Golden images contain the package and service assets only. Enrollment happens when a... - [About Deployment](https://docs.agentkeeper.dev/connect/fleet/browser/deployment.md): Enterprise deployment has two parts: force-installing the extension via MDM so it appears on every managed browser, and delivering a managed config so the extension self-enrolls without user... - [agentkeeper-managed-config.ps1](https://docs.agentkeeper.dev/connect/fleet/browser/windows-intune.md): Deploy the AgentKeeper browser extension to Windows devices managed by Microsoft Intune. This path force-installs the extension on Chrome and delivers the managed config so the extension... - [GPO login script: Set-AgentKeeperUserEmail.ps1](https://docs.agentkeeper.dev/connect/fleet/browser/windows-gpo.md): Deploy the AgentKeeper browser extension to Windows devices using Group Policy (GPO). This path works for on-prem Active Directory environments and is also compatible with Intune-synced hybrid AD... - [Macos jamf](https://docs.agentkeeper.dev/connect/fleet/browser/macos-jamf.md): Deploy the AgentKeeper browser extension to Jamf-managed Macs. This path uses a Jamf Configuration Profile to force-install the extension in Chrome and a separate Managed Preferences profile to... - [Macos intune](https://docs.agentkeeper.dev/connect/fleet/browser/macos-intune.md): Deploy the AgentKeeper browser extension to macOS devices managed by Microsoft Intune using a Settings Catalog policy for force-install and a Custom .mobileconfig profile for the managed config. - [Macos iru](https://docs.agentkeeper.dev/connect/fleet/browser/macos-iru.md): Deploy the AgentKeeper browser extension to Iru/Kandji-managed Macs using a Custom Profile for force-install and a Managed Preferences profile for the org API key. - [Macos multi browser](https://docs.agentkeeper.dev/connect/fleet/browser/macos-multi-browser.md): Deploy the AgentKeeper extension to every Chromium browser on a macOS fleet from a single Apple configuration profile. The profile force-installs the extension and delivers managed config... - [Google workspace](https://docs.agentkeeper.dev/connect/fleet/browser/google-workspace.md): For organizations using Google Workspace (formerly G Suite) with Chrome Browser Cloud Management, you can force-install the AgentKeeper extension and push its managed configuration directly from... - [Firefox](https://docs.agentkeeper.dev/connect/fleet/browser/firefox.md): Deploy the AgentKeeper Firefox extension through Firefox enterprise policy. On Windows and Linux, a policies.json file on disk is enough. On macOS, use an MDM configuration profile because modern... - [Verifying Deployment](https://docs.agentkeeper.dev/connect/fleet/browser/verify.md): Complete this checklist on a managed device after pushing the extension policy. A workstation is not considered fully connected until force-install, enrollment, and event delivery are all confirmed. - [Legacy MDM script migration](https://docs.agentkeeper.dev/connect/fleet/legacy-scripts.md): This page is for an existing generated-script assignment. New deployments use the signed OS package: - [Validate deployment](https://docs.agentkeeper.dev/connect/fleet/validate.md): Use this page after Windows, macOS, or Linux package deployment. Package-manager success is only the first checkpoint. AgentKeeper success requires fresh runtime health plus live evidence from the... - [Deployment test checklist](https://docs.agentkeeper.dev/connect/fleet/qa.md): Use this checklist to validate the Windows, macOS, or Linux enterprise installer on representative workstations before expanding a managed deployment. It covers clean installation, per-device... - [Uninstall and rollback](https://docs.agentkeeper.dev/connect/fleet/uninstall-rollback.md): Separate normal rollback from full removal. Rollback keeps AgentKeeper deployed but returns the endpoint to a previous approved package. Uninstall removes the runtime and AgentKeeper-owned hook... - [Uninstall AgentKeeper](https://docs.agentkeeper.dev/connect/fleet/uninstall.md): Quit Claude Desktop and Claude Code before uninstalling. Choose the exact installation track first: Windows package, universal macOS PKG, managed Linux RPM, or legacy standalone shell install. Do... - [Members and roles](https://docs.agentkeeper.dev/connect/identity/members-and-roles.md): The four AgentKeeper roles — owner, admin, member, developer — what each can do, how to invite people, and how roles relate to SSO. - [Directory sync](https://docs.agentkeeper.dev/connect/identity/directory-sync.md): Connect Microsoft Entra ID, Google Workspace, or Okta so AgentKeeper maps workstations to real people and groups. - [Single sign-on](https://docs.agentkeeper.dev/connect/identity/sso.md): Set up SAML 2.0 sign-in for the AgentKeeper dashboard with Okta, Microsoft Entra ID, Google Workspace, or any SAML IdP. - [Coverage overview](https://docs.agentkeeper.dev/surfaces/overview.md): Compare AgentKeeper hooks, Gateway routing, browser controls, plugins, telemetry, and discovery without treating audit evidence as pre-execution enforcement. - [How AgentKeeper works](https://docs.agentkeeper.dev/start-here/how-it-works.md): The path an agent action takes from a developer's keyboard to a policy decision and an audit record. - [What AgentKeeper sees](https://docs.agentkeeper.dev/start-here/what-agentkeeper-sees.md): AgentKeeper observes AI agent activity through the hook or gateway surface installed on the workstation. It does not claim visibility into actions an agent never emits, and it does not silently... - [IDE coverage](https://docs.agentkeeper.dev/connect/agents/ai-coding-agents.md): AgentKeeper monitors local IDE and coding-assistant activity across Claude Code, Cursor, Codex, Gemini CLI, Google Antigravity, VS Code Copilot, and Windsurf. Shell commands, file activity, MCP... - [IDE runtime parity](https://docs.agentkeeper.dev/connect/agents/ide-parity.md): AgentKeeper supports several coding-agent and desktop-agent surfaces, but they do not all expose the same enforcement hooks. Treat Claude Code as the baseline, then use this matrix to decide... - [MCP Gateway](https://docs.agentkeeper.dev/surfaces/mcp-gateway/mcp-gateway.md): The AgentKeeper MCP Gateway is a standalone Go binary that sits between your AI agent and your MCP servers, including Claude Chat in the Claude Desktop app. It gives security and platform teams... - [Install the MCP Gateway](https://docs.agentkeeper.dev/surfaces/mcp-gateway/install.md): The developer-convenience install path. One command, any macOS or Linux laptop, signed binary from GitHub Releases. - [Enterprise MCP Gateway install](https://docs.agentkeeper.dev/surfaces/mcp-gateway/enterprise-install.md): The fleet-deployment path for the AgentKeeper MCP Gateway. Written for IT and platform teams rolling the gateway out to 10+ workstations through a configuration-management or native package tool.... - [AgentKeeper MCP Server](https://docs.agentkeeper.dev/surfaces/mcp-gateway/agentkeeper-mcp.md): AgentKeeper MCP Server lets approved AI assistants query AgentKeeper evidence through a hosted, governed MCP endpoint. Use it when a SOC copilot, coding assistant, SOAR workflow, GRC assistant, or... - [Browser Extension](https://docs.agentkeeper.dev/surfaces/browser-extension.md): The AgentKeeper browser extension collects supported AI web sessions alongside the desktop runtime. Events flow into AgentKeeper Activity and policy decisions when a site adapter is enabled and... - [eBPF Runtime Sensor](https://docs.agentkeeper.dev/surfaces/os-runtime-sensor.md): The AgentKeeper eBPF Runtime Sensor gives AgentKeeper visibility into AI activity running inside Kubernetes clusters. It is for security and platform teams that need to know which workloads are... - [Claude OTLP Telemetry Setup](https://docs.agentkeeper.dev/surfaces/telemetry-setup.md): Send Claude Code and Claude Cowork OpenTelemetry logs into AgentKeeper as centralized telemetry evidence. OTLP adds Activity rows, cost and token context, MCP observations, detector findings, and... - [EDR Discovery](https://docs.agentkeeper.dev/surfaces/edr/edr-discovery.md): EDR Discovery imports read-only AI agent evidence from CrowdStrike and SentinelOne into AgentKeeper AI Discovery. - [CrowdStrike EDR Discovery](https://docs.agentkeeper.dev/surfaces/edr/crowdstrike.md): CrowdStrike EDR Discovery imports read-only Falcon endpoint evidence into AgentKeeper AI Discovery. - [SentinelOne EDR Discovery](https://docs.agentkeeper.dev/surfaces/edr/sentinelone.md): SentinelOne EDR Discovery imports read-only endpoint and Singularity Data Lake evidence into AgentKeeper AI Discovery. - [Runtime Shield](https://docs.agentkeeper.dev/protect/runtime-shield.md): Runtime Shield evaluates supported AI agent actions as they pass through each agent's hook surface. For pre-execution hooks it can Monitor, Warn, or Block before the action runs. For after-only or... - [Policy Profiles and packs](https://docs.agentkeeper.dev/protect/policy-packs.md): Policy Profiles are the customer-facing way to apply runtime controls to a specific audience without duplicating the organization-wide Base Policy. - [Policy outcomes](https://docs.agentkeeper.dev/protect/policy-outcomes.md): Monitor, Warn, Block, Policy Profiles, Controls, Detectors, Signals, and surface capability labels. - [Detections and coverage](https://docs.agentkeeper.dev/protect/detections.md): Understand what an AgentKeeper detector matches, where it can enforce, and how to interpret active, audit-only, bypassable, and unsupported coverage. - [Policy-gated exceptions](https://docs.agentkeeper.dev/protect/policy-gated-exceptions.md): Policy-gated exceptions are a governed security workflow for blocked runtime actions. They are not a developer bypass, and they do not grant developers access to AgentKeeper. - [MCP Activity](https://docs.agentkeeper.dev/protect/mcp-skills.md): MCP servers are the fastest-growing extension point in Claude Code, and the fastest-growing attack surface. Any MCP server can expose tools that read files, execute code, send data externally, or... - [Agent Inventory](https://docs.agentkeeper.dev/protect/agent-skills.md): Agent Inventory is a workstation-reported inventory of slash-skills (/skill-name), workstation MCP configuration, and installed agent plugins. It discovers installed agent surfaces at session... - [Prompt Vault privacy modes](https://docs.agentkeeper.dev/protect/prompt-vault/prompt-vault.md): Prompt Vault controls whether AgentKeeper retains raw user prompts after runtime policy evaluation. Detection still evaluates supported prompts in memory, then the retention mode decides what is... - [Prompt Vault admin guide](https://docs.agentkeeper.dev/protect/prompt-vault/admin-guide.md): Prompt Vault lives in Settings > Privacy. It is an organization-level control for raw user prompt retention across supported Runtime Shield prompt events and Claude/Cowork OTLP logs. - [Prompt Vault technical coverage](https://docs.agentkeeper.dev/protect/prompt-vault/technical-coverage.md): Prompt Vault is implemented as a central prompt-retention policy used by runtime hooks and OTLP ingest. The control governs raw user prompt text after detection and before normal event evidence is... - [Prompt Vault surface audit](https://docs.agentkeeper.dev/protect/prompt-vault/surface-audit.md): This page tracks where raw prompt text can move after ingestion and how Prompt Vault keeps protected modes from exposing it through normal evidence flows. - [Prompt Vault showcase](https://docs.agentkeeper.dev/protect/prompt-vault/showcase.md): Prompt Vault gives enterprise customers a concrete answer to the raw-prompt visibility question: AgentKeeper can detect risky prompts without making every prompt visible in normal telemetry. - [Control integrity](https://docs.agentkeeper.dev/protect/control-integrity.md): Control integrity covers attempts to disable, remove, weaken, or route around AgentKeeper on a workstation. It is the enterprise answer for situations where an AI agent suggests disabling a hook,... - [Dashboard](https://docs.agentkeeper.dev/investigate/dashboard.md): The AgentKeeper dashboard gives security teams one control plane for AI agent usage across workstations, repositories, and identity groups. - [Activity and investigations](https://docs.agentkeeper.dev/investigate/activity-investigations.md): Activity is the operational audit stream for runtime decisions. It is where admins confirm that an agent is connected, verify policy behavior, and start investigations when an event needs review. - [PASS and BLOCK events](https://docs.agentkeeper.dev/investigate/pass-block-events.md): AgentKeeper records different event types for different reasons. The most common enterprise confusion is seeing BLOCK events but not PASS events. - [AI Discovery](https://docs.agentkeeper.dev/investigate/ai-discovery.md): AI Discovery is the review and proof surface for AI found across workstations, browsers, runtime hooks, MCP, inventories, and MDM preseed evidence. - [Workstations](https://docs.agentkeeper.dev/investigate/workstations.md): Fleet management for every AI-agent workstation in your organization. Know who is using agents, what they are working on, whether their environment is hardened, and which versions are deployed... - [Claude OpenTelemetry Evidence](https://docs.agentkeeper.dev/investigate/otlp-evidence.md): Claude Code, the Claude Agent SDK, and Claude Cowork can send OpenTelemetry logs to AgentKeeper. Treat OTLP as a centralized telemetry input: it records Claude-reported activity, enriches Activity... - [Security model](https://docs.agentkeeper.dev/trust/security-model.md): AgentKeeper sits between supported AI agent actions and the organization policy that decides whether those actions pass, warn, or block. - [Installer release readiness](https://docs.agentkeeper.dev/trust/release-readiness.md): Check signing, release channel, provider validation, and broad-rollout state before assigning an AgentKeeper package to a fleet. - [Data handling](https://docs.agentkeeper.dev/trust/data-handling.md): AgentKeeper is designed to give security teams enough runtime evidence to govern AI agents without collecting more workstation data than the workflow requires. - [Trust and compliance](https://docs.agentkeeper.dev/trust/trust-compliance.md): Use this page for security review and rollout approval. It summarizes the AgentKeeper trust model and links to the detailed controls that answer privacy, evidence, enforcement, and audit questions. - [Network requirements](https://docs.agentkeeper.dev/trust/network-requirements.md): Use this page before assigning AgentKeeper through MDM, repo hooks, or gateway deployment. The goal is simple: endpoints must reach AgentKeeper for enrollment, policy, heartbeat, and runtime... - [Data Export](https://docs.agentkeeper.dev/trust/data-export.md): Configure Data Export to send selected AgentKeeper OTLP events to your Amazon S3 bucket. Use filters to control which events are included. - [API Reference](https://docs.agentkeeper.dev/api-reference/api-reference.md): Use the shipped AgentKeeper customer API for organization context, policy bootstrap, setup health, limited recent decisions, and eligible telemetry summaries. - [API architecture](https://docs.agentkeeper.dev/api-reference/architecture.md): Separate the supported customer read API from runtime ingestion, managed component protocols, dashboard internals, and planned contracts. - [Get API key context](https://docs.agentkeeper.dev/api-reference/get-api-v1-me.md): The role of the user who created this key, the organization name, and the plan. - [Get the Runtime Shield baseline policy](https://docs.agentkeeper.dev/api-reference/get-api-v1-shield-policy.md): The effective baseline policy for the key's organization. Returns platform defaults when the organization has not customized it. - [List policy pack templates](https://docs.agentkeeper.dev/api-reference/get-api-v1-policy-packs-templates.md): Metadata for the built-in Policy Profile templates. - [Get runtime hook health](https://docs.agentkeeper.dev/api-reference/get-api-v1-claude-code-health.md): Whether hooks are reporting for one agent surface, plus active hosts, active sessions, and the 24-hour event count. - [List recent blocked or warned events](https://docs.agentkeeper.dev/api-reference/get-api-v1-claude-code-recent.md): The most recent events that did not pass, newest first. - [Get telemetry activity status](https://docs.agentkeeper.dev/api-reference/get-api-v1-otlp-health.md): Whether OTLP and hook telemetry is arriving. Enterprise only. - [Diagnose OTLP setup](https://docs.agentkeeper.dev/api-reference/get-api-v1-otlp-setup-health.md): Samples recent OTLP events and reports how many carry the fields needed to map an event to a workstation and a person. Use it when telemetry arrives but does not appear against the right host. Enterprise only. - [Get usage and cost summaries](https://docs.agentkeeper.dev/api-reference/get-api-v1-otlp-usage-costs.md): Token usage and cost by team, by user, and flagged anomalies. Enterprise only. - [Runtime Integration API](https://docs.agentkeeper.dev/api-reference/runtime-integration-api.md): Use the Runtime Integration API when a hook, gateway, collector, or fleet script needs to send data into AgentKeeper or request a policy decision. These endpoints are intentionally POST-heavy... - [Webhooks](https://docs.agentkeeper.dev/api-reference/webhooks.md): Use webhook destinations when another security system needs high-signal AgentKeeper events without polling. They are the right fit for blocked activity, MCP gateway decisions, investigation... - [Changelog](https://docs.agentkeeper.dev/changelog.md): Every customer-facing AgentKeeper release, newest first: what shipped, what changed, and what it means for your fleet. - [Roadmap](https://docs.agentkeeper.dev/roadmap.md): What is shipped, in progress, and queued next for AgentKeeper. Targets, not commitments. - [Get help](https://docs.agentkeeper.dev/help/index.md): Where to look first when something is not working, which troubleshooting page owns which symptom, and how to reach a human. - [FAQ](https://docs.agentkeeper.dev/help/faq.md): Short answers to the questions we get most about prompts, blocking, plans, uninstalling, and what leaves the workstation. - [Contact support](https://docs.agentkeeper.dev/help/contact.md): How to reach AgentKeeper support, and the five things to include so the first reply actually solves your problem. - [Setup health](https://docs.agentkeeper.dev/help/setup-health.md): Setup health answers one question: is this workstation producing live runtime evidence for the AgentKeeper environment you are viewing? - [Missing activity events](https://docs.agentkeeper.dev/help/missing-activity-events.md): Use this guide when installation appears successful but Activity does not show the runtime events you expected. - [Enterprise install troubleshooting](https://docs.agentkeeper.dev/help/troubleshooting.md): Start with the symptom. Avoid rerunning broad installer logic until you know whether the failure is package, service, enrollment, policy, hook, live-event, or dashboard freshness. ## Português (BR) - [Documentação do AgentKeeper](https://docs.agentkeeper.dev/pt-br/index.md): Instale o AgentKeeper, defina políticas para agentes de IA de código e investigue o que esses agentes realmente fizeram na sua frota. - [Instalação](https://docs.agentkeeper.dev/pt-br/start-here/installation.md): Conecte uma estação de trabalho ao AgentKeeper, confirme que os hooks carregaram e veja o primeiro evento chegar ao dashboard. - [Runtime Shield](https://docs.agentkeeper.dev/pt-br/protect/runtime-shield.md): Como o Runtime Shield avalia ações de agentes de IA em tempo real e aplica Monitor, Warn ou Block antes que a ação seja executada. - [Resultados de política](https://docs.agentkeeper.dev/pt-br/protect/policy-outcomes.md): Monitor, Warn, Block, Policy Profiles, Controls, Detectors, Signals e rótulos de capacidade por superfície no AgentKeeper. - [Requisitos de rede](https://docs.agentkeeper.dev/pt-br/trust/network-requirements.md): Egress, protocolos, inspeção TLS, empacotamento offline e proxy a resolver antes de distribuir o AgentKeeper por MDM.