
Secure agents in seconds with permissions enforced at runtime.
Website | Documentation | Dashboard | Discord
AI agents do more than suggest code. They run shell commands, read files, call services, change infrastructure, and interact with production systems.
Kontext puts local policy between AI agents and the tools they call. It observes supported actions, evaluates policy before consequential actions run, and records the decision and outcome in an authorization ledger.
Start in observe mode. See what policy would stop. Move supported boundaries into enforcement when you are ready.
Policy evaluation errors allow the tool call, including in enforce mode, and remain visible as failures in the activity record. Completed policy denies and unavailable required approvals still block. This error fallback does not change behavior when the daemon is unavailable or enforcement has no usable policy.
Kontext currently supports Claude Code, Claude Cowork, and Codex. Exact event and enforcement coverage varies by agent—see the agent support matrix.
Managed Claude hooks recognize Cowork sessions with either full or shortened session directory names, preserving their Cowork identity in activity records.
brew install kontext-security/tap/kontext
Create an install token in the Kontext dashboard, then run:
kontext setup
The optional local risk model needs llama.cpp: run brew install llama.cpp, then kontext setup --with-local-llm.
Setup:
Verify the installation:
kontext doctor
Then keep using Claude Code or Codex normally. You do not need to launch the agent through a separate wrapper.
Self-serve setup currently supports macOS. Managed and cloud environments can run the same local runtime when they provide a supported hook contract, storage, and daemon lifecycle.
Without pre-action policy, an agent action executes before a security team can review its logs:
agent requests an action
|
v
action executes
|
v
activity appears in a log
With Kontext:
agent requests an action
|
v
Kontext receives it through a supported hook
|
v
local policy evaluates the action
|
+---- allow ----------> action continues
|
+---- would deny -----> action continues and evidence is recorded
| (observe mode)
|
+---- deny -----------> action is stopped before execution
(enforce mode)
|
v
decision and outcome enter the authorization ledger
This creates a decision point before the action, not only a record after it.
Blocking every unfamiliar action on day one creates noise and interrupts developers. Allowing every action indefinitely leaves policy as passive monitoring.
Kontext separates rollout into two modes:
Observe mode records the policy decision without interrupting the agent.
Use it to answer:
Enforce mode returns a real denial when a deterministic policy matches at a supported synchronous pre-action hook.
Policies can define boundaries around actions such as:
Enforcement is intentionally limited to event surfaces where the agent waits for Kontext before continuing. Kontext does not claim that receiving an event means it can stop every action from that agent.
Every supported event that reaches Kontext can contribute evidence to the local authorization ledger.
A record can include:
Kontext records tool activity and decision evidence. It does not capture model reasoning or reconstruct full conversation history.
Managed deployments can export redacted records to the Kontext dashboard for organization-wide review, retention, and investigation.
Ledger exports and idle heartbeats report the running daemon's CLI release as
device.cli_version, separately from the package marker in
device.deployment_version (or its self-serve fallback). A package marker update
does not change the reported CLI release until a daemon running the new binary
sends telemetry.
The decision path stays local:
Claude Code / Cowork / Codex
|
v
supported hook
|
v
local Kontext runtime
|
+-----+------+
| |
v v
policy decision local ledger
|
v
allow / would deny / deny
A hosted service does not need to answer every tool call.
Managed deployments add organization configuration, policy rollout, record export, identity, and retention. They do not move the synchronous decision path out of the agent environment.
“Supported” means more than accepting an event. Kontext documents which events it receives, which events can block, and how each integration is installed.
| Agent | What Kontext records | Pre-action blocking | Installation |
|---|---|---|---|
| Claude Code | Session lifecycle, pre-tool-use, successful and failed post-tool-use | Pre-tool-use | Installed by kontext setup |
| Codex | Session start, pre-tool-use, post-tool-use, prompt submission, stop | Pre-tool-use | Installed by kontext setup; hooks must be trusted in Codex |
| Claude Cowork | Claude Code-compatible session and tool events | Pre-tool-use | Configure the hook inside the Cowork environment |