Connect an agent

Put the same guardrails on every agent your team runs, and optionally see them all in one workspace. Each connector checks actions and keeps receipts on your side first.

AgentPackageChecked before it runsNot covered
Claude Code, Cursor@scopebond/hookCommands, file access, MCP tools, web fetchesProcesses started outside the agent. Cursor file edits are flagged, not prevented
OpenAI Codex@scopebond/hookLocal commands, file changes, MCP toolsHosted web tools and Codex cloud runs
Your own agent@scopebond/gatewayActions sent through the gatewayAnything reached without the gateway
MCP servers@scopebond/mcpTool callsResource reads and prompts
Agent frameworks@scopebond/frameworkWrapped tool callsCode outside the wrapper
GitHub pull requests@scopebond/github-actionAgent pull requests, before mergeWork already done in the agent's sandbox

All six work locally today. The workspace Add agent step covers the first three. [PLANNED] The other three in the workspace.

Claude Code, Cursor or Codex

  1. In the workspace, open Agents → Add an agent, pick the tool and name the agent (or add it on the approval page in step 3).
  2. On the computer where you use the agent, open your own terminal (not inside the agent), go to your home folder and run the sign-in command. On Windows type it with .cmd, exactly as shown: PowerShell's default script policy blocks plain npx.

Windows PowerShell (in Command Prompt, use cd /d %USERPROFILE% instead of cd ~):

``powershell cd ~ npx.cmd -y @scopebond/hook@latest login <workspace-url> # add --cursor or --codex ``

macOS or Linux:

``bash cd ~ npx -y @scopebond/hook@latest login <workspace-url> # add --cursor or --codex ``

  1. It prints a workspace link and a code. Open the link in your browser. Check that the code matches, choose the agent and approve within 10 minutes. The page then shows the computer connecting, its first action and the Scopebond Agent's self-check.
  2. For Codex, open Codex, run /hooks, and choose Trust.
  3. Start a new session and ask the agent to do one safe action. It shows as connected in Agents.

Signing in sets up the whole computer. It adds the Scopebond hook to your user-level agent settings (%USERPROFILE%\.claude\settings.json on Windows, ~/.claude/settings.json elsewhere; likewise .cursor\hooks.json and .codex\hooks.json), so every project is checked, and it keeps everything else in that file. The machine credential is saved in .scopebond\cloud.json in the same home folder; never share or commit it. npx.cmd -y @scopebond/hook@latest status (npx on macOS and Linux) then shows when this computer last delivered records and anything waiting to send. If a step fails, the When something goes wrong table gives the cause and the one command that fixes it.

Then start the Scopebond Agent with your sign-in; it is part of the standard install. It runs in the background for your user: it sends waiting records, keeps the connection and rules current, moves Scopebond to the version your workspace names, puts back a lost hook entry and checks once a day that everything works end to end. On Windows it shows a green, amber or red tray icon with the one fix in its menu; on macOS and Linux it notifies you when something needs attention. Where your workspace lets people override a blocked action, it shows the window where you allow it with a reason. The hook keeps deciding every action even when the agent is not running.

Windows (PowerShell or Command Prompt):

npm.cmd install -g @scopebond/agent@latest
scopebond-agent.cmd autostart on
scopebond-agent.cmd status

macOS or Linux:

npm install -g @scopebond/agent@latest
scopebond-agent autostart on
scopebond-agent status

status should say the computer is connected and that the agent starts with your sign-in.

To check one project only, without a workspace, run npx.cmd -y @scopebond/hook@latest init in the project root (npx on macOS and Linux) (init --shared gives the whole team the setup through git).

A computer without a browser can use a one-time setup command instead: Use a one-time setup command instead on the Connect page. Its key is single use, expires after about 15 minutes, and should stay out of chat.

Your own agent: the gateway

Run the open-source gateway in front of the tools or APIs your agent uses. It denies anything unsigned, unknown or outside your policy.

npx -y @scopebond/gateway@latest init

On Windows, type npx.cmd instead of npx in PowerShell.

init writes an agent key and a starter policy, and prints the start command. Keep the printed token and the key out of source control. For the workspace, choose Add agent → Self-hosted gateway. Full setup: https://github.com/avouro-com/scopebond.

MCP servers

Put the proxy between your MCP client and the server. A denied tool call never reaches the server.

npx -y @scopebond/mcp@latest --server filesystem --policy scopebond.policy.json --key scopebond-agent.key \
  -- npx -y @modelcontextprotocol/server-filesystem /path/to/workspace

On Windows, type npx.cmd for both. To install the proxy once instead: npm install -g @scopebond/mcp@latest (npm.cmd on Windows), then run scopebond-mcp.

Agent frameworks

Wrap your tools once. A denied call returns a refusal to the model instead of running.

import { createToolGuard, wrapVercelTools } from "@scopebond/framework";
const guard = createToolGuard({ policy, agentKeyPem, manifest: { transfer: "payout.create" } });
const tools = wrapVercelTools(myTools, guard); // also LangGraph and OpenAI tools

GitHub pull requests

Add the action to a read-only workflow on pull_request_target that checks out the base commit. Make it a required check. The policy comes from the base commit, so a pull request cannot loosen its own rules.

- uses: actions/checkout@v4
  with: { ref: "${{ github.event.pull_request.base.sha }}", fetch-depth: 0 }
- uses: avouro-com/scopebond/packages/github-action@main  # or pin a commit
  with: { policy: scopebond.policy.json }

Agent pull requests (Copilot, Devin, Codex, Cursor, Claude) are checked. People's pull requests are never blocked. For Cursor, this stops an out-of-policy edit from merging.

After connecting

Open Activity to see each receipt, Rules for recommended rules per agent, and Settings to set alerts by email, Slack or webhook.

Check a computer from your workspace

  • Right after you approve, the approval page keeps following that computer: it finished connecting, its first action arrived, and the Scopebond Agent's self-check passed. A step still waiting after two minutes shows the one thing to do, in the form your system runs. You can close the terminal; the page keeps checking for 30 minutes and then offers Check again.
  • Agents → Computers lists every computer. Needs attention names the most important problem on a computer: records missing, a failed self-check, or the Scopebond hook set up twice. Overview counts those computers under Next steps.
  • Open a computer to see "This computer": its versions, its last self-check, and the one fix, most important first.
  • Records missing since …: the computer numbers every record, and some numbers never arrived. Run scopebond-agent.cmd flush on it (macOS and Linux: scopebond-agent flush; without the agent, the hook's flush). If it says nothing is waiting, they were lost on that computer and the line stays as the record of the gap.
  • Lost on the computer: the computer's delivery queue was removed before some records were sent. They cannot be recovered; the count says how many and when it was seen.
  • A computer that signed in again shows its old connection as replaced, and one you disconnected shows as disconnected. Neither needs anything.