Guides
How to govern and audit AI coding agents — Claude Code, Cursor, MCP and agent pull requests — with fail-closed rules and signed records you can verify offline.
For developers
- How to audit what Claude Code does
See and log every action Claude Code takes on your machine. Install a PreToolUse hook that records a signed, offline-verifiable receipt of each tool call — no account, no network. - Block Claude Code from dangerous commands
Stop Claude Code from running rm -rf, force-pushing to main, or reading secret files — before the command runs. A hook that decomposes shell commands so a denied program can't ride in behind an allowed one. - Cursor hooks: govern what Cursor's agent can do
Control Cursor's agent with hooks. One command registers a Scopebond hook in .cursor/hooks.json that checks each shell, file and MCP action against your policy and blocks the out-of-policy ones. - Is Claude Code safe to use at work?
Claude Code is as safe as the guardrails around it. An honest checklist for using it at work: managed settings, a fail-closed checkpoint that blocks destructive actions, secret-file protection, and a signed audit trail. - Is Cursor safe to use at work?
Cursor's agent can run commands and edit files. An honest checklist for safe use at work: review auto-run settings, add a fail-closed hook, protect secrets, and keep a signed record. - A GitHub required check for AI-agent pull requests
Fail an AI agent's pull request when it breaks policy, before it can merge. Add the Scopebond GitHub Action as a required status check that runs in your own runner and signs a record. - Prove what an AI coding agent did
A log a vendor can edit is a claim; a signed record is evidence. Scopebond signs every agent decision into a tamper-evident receipt anyone can verify offline, with no account. - Govern MCP tool calls with one policy
Put a policy in front of every Model Context Protocol tool call. @scopebond/mcp is a proxy that checks each tools/call against your policy before it runs and signs the decision. - How Scopebond compares
Scopebond vs Microsoft Agent Governance Toolkit, Agent Receipts, ThumbGate, Endor Labs and hand-written hooks.
For teams and owners
- AI use policy template for coding agents
A short, adaptable AI-use policy for teams whose developers use Claude Code or Cursor. The coding-tool section maps to enforceable rules; the rest stays advisory — and we say which is which. - What is shadow AI?
Shadow AI is employees using AI tools without the organization's knowledge or guardrails. For coding agents that means ungoverned actions and no record. Here's a practical way to get ahead of it. - AI governance tools for small teams
Small teams don't need an enterprise GRC platform to govern AI coding agents — they need guardrails that block dangerous actions and a record they can show. What to look for and how to start. - When an AI coding agent does something it shouldn't
A calm, practical incident checklist for when an AI coding agent takes a harmful action: contain, find out what happened from the record, assess, remediate, and prevent recurrence with a rule. - AI use policy generator
Generate an editable company AI-use policy for coding agents; the enforced clauses map to real Scopebond rules.