Platform
One decision point, where the action actually happens.
Your identity provider decides who an agent is. Your secrets manager decides what it can hold. Evren decides what it can do on the machine — and proves what it did.
01 · Decide
Execution boundary
Every privileged action is evaluated against a compiled, signed policy before anything runs. A permit is a decision, not a door held open for the rest of the session.
- Per-call decisions, not per-session grants
- First-match policy, compiled and MAC-verified
- Denials are inline — the agent keeps working
02 · Confine
Process isolation
What the daemon permits runs inside a sandbox armed before exec. If the confinement a rule names cannot be applied on that host, the command does not run at all.
- seccomp default-deny syscall allowlist
- Landlock filesystem confinement — listed paths only
- Fail-closed: the filter arms, or the command aborts
03 · Attribute
Agent identity
Policy matches on which agent is asking, not which user account it happens to run under. Five agents on one service account are five identities, not one.
- SPIFFE attestation as a first-class policy predicate
- Process-ancestry floor — a child never exceeds its parent
- Works with the identity your IdP already issues
04 · Prove
Signed audit
One record per decision — permits as well as denials — signed and hash-chained, on its way off the box before anything spawns.
- ed25519-signed, hash-chained, verifiable offline
- Streamed off-host over mTLS to a WORM sink
- Tamper-evident under host root: detection and bounded loss
Where it matters first
Most teams did not procure these. They arrived with an approved tool and a developer’s laptop.
Coding agents
Claude Code, Copilot and anything else with a terminal. They install packages, restart services and spawn shells — because that is the job you gave them.
CI/CD runners
Build agents hold standing privilege on shared hosts and run whatever the pipeline hands them. One compromised dependency reaches everything on the runner.
SRE automation
Runbook agents act on production at machine speed, at hours when nobody is reviewing. The remediation and the outage look identical until afterwards.
Vendor agents
Third-party agents arrive with an approved SaaS integration. You did not write them, cannot inspect them, and did not scope what they touch.
Start with thirty days of visibility
The first thing we deploy denies nothing. You see what your agents actually do, then decide what to change.