Getting started · visibility, control, and evidence
Start with one agent.
See oversight in action.
Create your workspace, connect an AI coding tool, and see its activity, rules, and signed records in one place.
Start with one agent on the Free plan. No card needed to get started. New workspaces include a 14-day Team trial; afterward, keep one agent on Free or choose a paid plan.
Your workspace comes first
- 1Create your workspaceSign in with Google, Microsoft, or GitHub. Use the account you want to own the workspace, or the account your team invited.
- 2Add your first agentIn the workspace, open Agents → Add an agent. Choose Claude Code, Cursor, or Codex and give it a name. One AI tool used by one person counts as one agent.
- 3Install on the computer you useFollow the four install steps below, in your own terminal or with the prompt for your AI tool. Open the link the sign-in prints, check the code, and approve the connection to your agent.
Exploring first? Open the sample workspace with fictional activity, no account required.
Install on your computer
You install two small parts from npm, on the computer where your AI tool runs: the Scopebond hook, which checks each action your coding tool takes, and the Scopebond Agent, which starts with your sign-in and keeps this computer connected, up to date and checked. Both are set up for your user across projects; you do not run them in every repository.
Run these in your own terminal, or let your AI tool run them with the prompt below. Either way, you approve the connection yourself in the browser. The commands select the latest published release; after that, the Scopebond Agent keeps the version your workspace names.
One command
It checks Node.js, connects your coding tool with a code you approve in the browser, installs the Scopebond Agent and starts it with your sign-in, then shows that everything is connected. Run it again any time: it only repairs what is missing. Add --cursor or --codex for those tools.
macOS or Linux
npx -y @scopebond/agent@latest setup https://cloud.scopebond.comWindows (PowerShell or Command Prompt)
npx.cmd -y @scopebond/agent@latest setup https://cloud.scopebond.comManual install
1. Check Node.js
Scopebond needs Node.js 22.13 or later. Check with the command below; if it is missing or older, install the current Node.js LTS release.
node --version2. Connect your coding tool
Run it from your home folder, not inside a project: first cd ~ (PowerShell, macOS, Linux) or cd /d %USERPROFILE% (Command Prompt). The command prints a link and a short code. Open the link, check that the code matches, choose your agent and approve. The command finishes on its own.
On Windows, type npx.cmd instead of npx in PowerShell: its default script policy blocks npx, and npx.cmd works in PowerShell and Command Prompt alike.
Connect Claude Code to your workspace. Open the link printed in your terminal, confirm the matching code, choose your agent, and approve.
macOS or Linux
npx -y @scopebond/hook@latest login https://cloud.scopebond.comWindows (PowerShell or Command Prompt)
npx.cmd -y @scopebond/hook@latest login https://cloud.scopebond.comThe hook is added to your user-level settings. Existing settings are preserved. The workspace receives activity records; prompts, file contents, and secrets stay out of those records.
Start a new session after setup. Supported commands, file access, and MCP tools are checked against the configured rules.
Connect Cursor to your workspace. Open the link printed in your terminal, confirm the matching code, choose your agent, and approve.
macOS or Linux
npx -y @scopebond/hook@latest login https://cloud.scopebond.com --cursorWindows (PowerShell or Command Prompt)
npx.cmd -y @scopebond/hook@latest login https://cloud.scopebond.com --cursorThe hook is added to your user-level settings. Existing settings are preserved. The workspace receives activity records; prompts, file contents, and secrets stay out of those records.
Start a new session after setup. Cursor file edits are recorded for review; use a required GitHub check to stop an out-of-policy edit from merging.
Connect Codex to your workspace. Open the link printed in your terminal, confirm the matching code, choose your agent, and approve.
macOS or Linux
npx -y @scopebond/hook@latest login https://cloud.scopebond.com --codexWindows (PowerShell or Command Prompt)
npx.cmd -y @scopebond/hook@latest login https://cloud.scopebond.com --codexThe hook is added to your user-level settings. Existing settings are preserved. The workspace receives activity records; prompts, file contents, and secrets stay out of those records.
For Codex, open /hooks, review Scopebond, and choose Trust. Start a new task. Local Codex actions are supported; cloud tasks need a required GitHub check at merge.
For agent pull requests, add a check in your own GitHub runner and make it required in your branch ruleset. Commit a reviewed scopebond.policy.json to the base branch first.
# .github/workflows/scopebond.yml
name: Scopebond
on: pull_request_target
permissions:
contents: read
pull-requests: read
jobs:
scopebond:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
ref: ${{ github.event.pull_request.base.sha }}
fetch-depth: 0
- uses: avouro-com/scopebond/packages/github-action@main
with:
policy: scopebond.policy.jsonThis checks out the base commit and never runs the pull request’s code. Keep it read-only; do not add a checkout or execution of the PR head. Pin the Scopebond Action to a reviewed full commit SHA for your rollout. Work inside a cloud agent’s sandbox is outside this check. Action setup and example policy.
For an MCP server, create its signing key and starter policy first. Replace <server-id> with the server’s name, then put the proxy in front of the real server in your MCP client settings.
npx -y @scopebond/mcp@latest init --server <server-id>npx -y @scopebond/mcp@latest --server <server-id> -- <your MCP server command>
Review the generated policy before use and keep the key private. Only tool calls are checked; resource reads and prompts are outside this connection. MCP workspace enrollment is a separate setup requiring an enrollment bundle; it is not the coding-tool sign-in above. Full MCP setup and policy reference.
3. Keep it connected: start the Scopebond Agent with your sign-in
The Scopebond Agent runs in the background for your user. It sends waiting records to your workspace, keeps the connection and rules current, moves Scopebond to the version your workspace names, and checks once a day that everything works end to end. On Windows it shows a tray icon: green when all is well, amber or red with the one fix in its menu. On macOS and Linux it notifies you when something needs attention. Where your workspace lets people override a blocked action, the agent shows the window where you allow it, with a reason.
macOS or Linux
npm install -g @scopebond/agent@latest
scopebond-agent autostart onWindows (PowerShell or Command Prompt)
npm.cmd install -g @scopebond/agent@latest
scopebond-agent.cmd autostart onautostart on starts the agent now and every time you sign in, with no window. The hook keeps checking actions even when the agent is not running; records then wait on this computer until it is. The agent on npm.
On Windows, if PowerShell then says scopebond-agent.cmd is not recognized, npm's folder is not on your PATH (common on a standard Windows account). Start it once by its full path: & "$env:APPDATA\npm\scopebond-agent.cmd" autostart on (Command Prompt: "%APPDATA%\npm\scopebond-agent.cmd" autostart on). Its autostart entry remembers where it is.
4. Check it
Both should say the computer is connected, and the agent should say it starts with your sign-in. Then start a new session of your AI tool so Scopebond starts checking it.
macOS or Linux
scopebond-agent status
npx -y @scopebond/hook@latest statusWindows
scopebond-agent.cmd status
npx.cmd -y @scopebond/hook@latest statusIf something is wrong, npx -y @scopebond/hook@latest doctor (Windows: npx.cmd -y @scopebond/hook@latest doctor) says what and how to fix it. Detailed connection guide.
Other runtimes — a self-hosted gateway for any agent over HTTP, framework plugins — are on the integrations page. Planned connectors are on the roadmap, with honest status.
Prompt to use for your AI agent to install
Prefer to let your AI tool do the typing? Copy this prompt into Claude Code, Cursor or Codex, fill in the two blanks, and send it. It runs the same steps as above and stops for you at the one step only you can do: approving the connection in your browser.
Help me install Scopebond on this computer, exactly as https://scopebond.com/get-started describes. Go one step at a time, show me each command before you run it, and stop and show me the exact error if a step fails.
I use: [Claude Code / Cursor / Codex]. My operating system: [Windows / macOS / Linux].
On Windows, use npx.cmd, npm.cmd and scopebond-agent.cmd instead of npx, npm and scopebond-agent (PowerShell's default script policy blocks the others).
1. Check Node.js: run `node --version`. It must be 22.13 or later. If it is missing or older, stop and tell me to install the current LTS release from https://nodejs.org.
2. Connect my coding tool to my Scopebond workspace, from my home folder and never inside a project (first cd ~ in PowerShell, macOS or Linux; cd /d %USERPROFILE% in Command Prompt). Run:
npx -y @scopebond/hook@latest login https://cloud.scopebond.com
Add --cursor for Cursor or --codex for Codex. The command prints a link and a short code, then waits up to 10 minutes for me to approve. Run it so it can keep waiting (in the background if your tool would otherwise stop it), show me the link and the code, and wait until it says it is connected. I open the link, check the code, choose my agent and approve. Never approve it yourself or open the link for me.
3. Keep it connected: install the Scopebond Agent and start it with my sign-in:
npm install -g @scopebond/agent@latest
scopebond-agent autostart on
4. Check it: run `scopebond-agent status` and `npx -y @scopebond/hook@latest status`. Tell me whether it is connected, whether the agent starts with my sign-in, and anything either one reports as a problem.
Rules while you help:
- Do not edit my coding tool's settings files or anything in the .scopebond folder by hand; the commands above do that.
- Do not change Scopebond's rules or turn any protection off.
- When you are done, tell me to start a new session of my coding tool so Scopebond starts checking it. For Codex, also tell me to open /hooks in Codex, review Scopebond and choose Trust.Your AI tool can run these commands, but it cannot approve the connection for you. Once the hook is installed, it also stops the AI tool from switching the hook off, editing Scopebond's settings or uninstalling Scopebond; that protection is always on, while every other rule records until you turn it on. Read each command before you let it run.
See your first recorded action
- 1Try one harmless taskStart a new AI-tool session and ask it to list the project files. Check Agents for the connection and Activity for the recorded action.
- 2Review the rulesSee which actions are monitored and which can be blocked. Choose protection deliberately for supported actions; recording an action alone does not stop it.
- 3Keep one agent on FreeStart with the activity and evidence for one tool. Your workspace lets you add teammates or choose a larger plan when you need it.
Prefer a local-only setup?
The open-source hook also works without a workspace. For one project, run npx -y @scopebond/hook@latest init in that project’s root; add --cursor or --codex for your tool. To set up the user across projects, use npx -y @scopebond/hook@latest install. For Codex, review and trust Scopebond in /hooks.
Keep signed records locally with npx -y @scopebond/hook@latest log and verify them with npx -y @scopebond/hook@latest verify. Creating a workspace adds shared visibility and review. Create your free workspace.
Bring your first agent into view.
Start free, connect your coding tool, and see visibility, control, and evidence working together.