Coding agents

Your coding agents have access. Security needs context.

Coding agents operate inside the developer trust boundary. Pavri adds agent-specific context to discover assistants, govern configured MCP and endpoint actions, and reconstruct sessions.

Pavri coding-agent coverage focuses on managed developer endpoints across macOS, Windows, Linux, with assistant discovery, MCP visibility, workspace context, policy, local evidence, and investigation. Observation and enforcement depth varies by OS, assistant, permissions, action type, and control point.

Endpoint context

Distinguish coding-agent activity from ordinary developer activity.

Pavri connects assistant identity to user, endpoint, workspace, repository, process, file, network, browser, credential, Git, MCP, policy, and session evidence where those sources are available.

macOS

Managed endpoint coverage with OS-specific observation sources, controls, deployment requirements, and known differences.

Coverage matrix defines current depth

Windows

Managed endpoint coverage with OS-specific observation sources, controls, deployment requirements, and known differences.

Coverage matrix defines current depth

Linux

Managed endpoint coverage with OS-specific observation sources, controls, deployment requirements, and known differences.

Coverage matrix defines current depth
Local components

Local MCP Broker, PolicyCache, and local evidence/WAL are endpoint-sensor components.

Configured MCP tool calls can be held for approval through the Local MCP Broker. PolicyCache supports local policy evaluation. Local evidence and write-ahead logs preserve events for upload and investigation.

Broker-routed MCP approval

Cursor asks prod-deploy to run mcp.deploy. Policy PROD-DEPLOY-04 holds the configured MCP tool call for approval through the Local MCP Broker.

Control point: local MCP broker
Coverage detail

Endpoint operating-system detail and accessible coverage matrix.

Coding-agent endpoint detail

macOS coding-agent coverage detail
Observation sourceAssistant, process, workspace, file, Git, network, browser, MCP, and local evidence sources where permissions allow.
Inline controlsLocal MCP Broker controls configured MCP calls; endpoint controls vary by action and entitlement.
Deployment requirementsManaged endpoint enrollment, endpoint sensor, PolicyCache, and approved privacy configuration.

Coverage depth varies by OS, assistant, permissions, action type, and control point.

Next step

Review coding-agent exposure before it becomes an incident.

Start with MCP, workspace, repository, terminal, credential, and production-action context.