How Scopebond works
Scopebond records what your AI agents do, stops the risky actions you choose before they run, keeps a signed record of every decision you can prove later, and gives your team one place to see every agent. This page explains how, and where the limits are.
Prevent: check each action before it runs
Scopebond sits between the agent and the tools it uses. Before each action, it checks the action against your policy and either lets it run or blocks it. A blocked action never runs, and the agent is told why.
For coding agents, every rule starts on Monitor: it records what it would have blocked and stops nothing until you turn it on. One protection is always on: a coding agent can never change Scopebond's settings, switch off the Scopebond Agent or uninstall Scopebond.
You choose where the check happens:
| Where | Best for | What it stops |
|---|---|---|
| Hook in Claude Code, Cursor or Codex | Coding agents | Commands, file access, MCP tools and web fetches |
| Gateway in front of your tools or APIs | Your own agents, and anything that touches money | Every action sent through it |
| MCP proxy or framework plugin | Agents built on MCP or a framework | Tool calls that pass through it |
| GitHub check | Agent pull requests | Out-of-policy changes from merging |
You run the open-source gateway yourself, so credentials stay with you. Its kill switch stops one agent or all of them.
What it does not cover: programs started outside the agent, or tools reached without Scopebond. The hook reads the command, not what a program does once it runs. It is a guardrail, not a sandbox. In Cursor, file edits are flagged but not prevented.
Prove: a signed receipt for every decision
Every decision, allowed or blocked, becomes a receipt: a signed record of what the agent tried, what was decided, and which policy decided it. Anyone can check a receipt offline with a public key, without trusting Scopebond. Changing or deleting a receipt shows. Secrets are removed before a receipt is signed, and file contents are never stored.
Receipts belong to you. Each one says how strong its evidence is, and never claims more. See Receipts and verification.
See: the hosted workspace
The workspace brings every agent's receipts into one view. It observes and reports. It never blocks anything, so an outage never changes a decision. Anyone can start a workspace at cloud.scopebond.com.
| Area | What your team gets |
|---|---|
| Overview | What needs attention, and the next step |
| Agents | Every agent, and its Computers tab: each computer, what its state means and what to do next |
| Activity | Each receipt, with evidence exports |
| Review | One tab each: Findings (open findings to review, highest severity first, each with a plain reason for its place and a review step (needs review, waiting for information, ready to close), and which agents to review first, with every risk factor shown. A review priority, not a score. Optional review times per severity (Settings → Notifications) give findings a due time); Requests to let one blocked action through; Rule changes (your team's drafts waiting for a reviewer); Agents to watch. A change to Block that needs a second person waits on the Rules tab |
| Reports | A monthly summary |
| Rules | One page: Rules sets Block or Monitor for each built-in rule, for all agents, an environment or one agent; Library explains every built-in rule and detection and the business risk it covers; Exceptions, Custom rules, Test, and Overrides & limits (the override window and action budgets) |
| Settings | Workspace, People & access (members and roles, Invite your team), Notifications (alerts by email, Slack or webhook), Data & evidence (Your data export), Billing and the Audit log; workspace deletion by the owner, with 7 days to undo |
Help, the documentation and the public record verifier are in the account menu at the top right.
An observed action is never shown as allowed, and counts are real or absent.
Where a workspace's data is stored
Each workspace keeps its records in one region, chosen when the workspace is created and shown under Settings → Workspace. The region cannot be changed later. To move, create a workspace in the other region and ask support to export your records and import them there. Your sign-in, your membership list and billing are held once, globally, so one account reaches workspaces in either region.
[PLANNED] The European Union region. Today every workspace is in the United States.
Where it stands
Scopebond is an experimental alpha for controlled test use. The hook, gateway and connectors are published on npm. The hosted workspace is in beta. Paid plans exist, but billing is not open yet.
[PLANNED] A performance collateral deposit that a principal could recover from after a proven policy breach. Nothing you use today depends on it.