PyxGrant / Pilot

A pilot on one team's coding agents.

One team, the laptops and CI runners they work on, and the MCP servers they use. Two weeks watching, then enforcement. This page lists what is in scope, how setup works, what we measure together, and what the product won't do.

Scope

Small enough to finish, real enough to judge.

WHO

One engineering team

Developers running Cursor, Claude Code, or CI agents with MCP tools, and the security owner who reviews what gets refused or held.

WHERE

The machines they already use

One Go binary on each laptop and CI runner. The policy, the approvals, and the audit log stay on that machine. pyxgrant console gives the security owner one view across them.

IN

What the pilot covers

  • Finding the team's agents and MCP servers
  • The MCP proxy on the servers you choose
  • The Claude Code and Cursor hook for built-in shell and file tools
  • Held calls, approvals, freeze, and the signed audit log
OUT

What it leaves out

  • Host-wide file and syscall monitoring. Your EDR keeps it.
  • Kernel-level enforcement on the endpoint
  • Vendor-built SaaS or plant connectors
  • A highly available console
Setup

Watch first, then enforce.

The pilot starts in observe mode. PyxGrant decides every routed call exactly as it would, records what it would have refused or held, and lets the call through. Redaction still applies.

  1. Install and check.Put the binary on each machine, write a starting policy, and confirm the host is ready. pyxgrant policy init pyxgrant selftest
  2. Find what's running.List the coding agents on each machine, every MCP server they load, ungoverned local model ports, and any plaintext secrets in their configs. pyxgrant agents scan pyxgrant discover
  3. Route the tools.Rewrite each MCP client config so its servers run behind PyxGrant, moving tokens into the OS vault, and install the hook for built-in tools. pyxgrant wrap -config .cursor/mcp.json -vault
  4. Observe for two weeks.Set "enforcement": "observe" in the policy. Nothing is refused or held. Each call it would have stopped is recorded as an observe: finding.
  5. Tune, then enforce.Propose a least-privilege policy from what the team actually used, check it against the recorded calls, then switch to enforce. pyxgrant policy learn pyxgrant replay -candidate new.json

The quickstart has the exact commands →

What we measure together

Success criteria you can check from the record.

Every number below comes from records the pilot produces on your machines, not from our reporting.

01

Coverage

How many of the team's agents and MCP servers were found and routed, and which still run outside PyxGrant. pyxgrant processes lists the ones running right now.

02

Wrong refusals

Every observe finding is reviewed before enforcement starts. Each one that shouldn't have fired is counted and fixed with a policy change. pyxgrant stats

03

Added time per call

What the gateway adds on your hardware, at the median and the slow tail. pyxgrant perf

04

Independent check

Your auditor verifies the hash chain and a sample of receipts with your public key, without help from us. pyxgrant audit

Limits to plan around

  • Observe mode protects nothing. It is a trial. Calls it would refuse still go through, so run it where that is acceptable, and keep it short.
  • Enforce mode fails closed. A held call that nobody answers is refused after ten minutes. pyxgrant wrap -undo restores a machine's original config.
  • Only routed actions are seen. An agent without the hook, or a server left out of the config, is not. pyxgrant reconcile names calls that went around it, if you supply the provider's audit export.
  • Detection has edges. Data protection is pattern-based, and prompt injection is not solved.

Before you install anything

  • A security review against this build, including pyxgrant boundaries, the product's own list of what it doesn't do
  • The pilot scope, success criteria, and support terms agreed in writing
  • A named contact on each side for refusals that block work

What each path covers →

Plan a pilot.

Tell us which agents and MCP servers the team uses. We'll come back with a written scope against this build.