HOL Guard for enterprises
Deploy AI coding agents without giving up control.
Guard Local enforces policy on the developer machine without any cloud dependency. Guard Cloud adds dashboards, shared policy, and org-wide telemetry on top of that local enforcement. You control the boundary.
Who this is for
Software companies using multiple AI coding tools across the team and needing consistent policy enforcement.
Teams with meaningful access to source code, credentials, infrastructure, or regulated data where an agent action could cause real harm.
A named buying committee that can own the rollout decision and sign off on the exit criteria at each stage.
Four proof questions
Control boundary
What can an AI agent do without a human decision, and what requires explicit approval? Guard makes the boundary visible and auditable.
Developer workflow
Does enforcement add friction that breaks flow? Guard wraps the existing harness setup and adds a pre-flight check, not a replacement workflow.
Evidence
Can you prove what the agent did and what was approved? Guard keeps a local decision trail and exports evidence to Guard Cloud for audit.
Deployment and operations
Who owns rollout, monitoring, and incident response? The deployment review names an owner and defines the exit decision at each stage.
Guard Local vs Guard Cloud
Guard Local
Runs entirely on the developer machine. Enforces policy on AI agent actions without any cloud dependency. Keeps a local decision trail. The plugin-scanner is the scanner engine that inspects MCP tools and extensions at launch time.
- Enforces locally — no cloud required for blocking
- Local decision trail for what was approved and what changed
- Free for individual developers
Guard Cloud
Adds shared policy, org-wide telemetry, and team dashboards on top of the local enforcement layer. Cloud connectivity is for visibility and coordination, not for enforcement.
- Shared policy across the team or organization
- Centralized dashboards and alert routing
- Evidence export for audit and compliance review
Deployment paths
Each stage is bounded with clear success criteria, a named owner, and an exit decision. No stage auto-advances.
Team evaluation (2-week trial)
Install Guard Local on a small set of developer machines with a limited harness set. Run smoke tests, collect evidence from the local decision trail, and review with the named owner. Exit decision: proceed to department rollout or adjust scope.
Department rollout
Extend to a full department with shared policy via Guard Cloud. Monitor dashboards for enforcement coverage and incident response. Exit decision: proceed to full org rollout or hold.
Full org rollout
Organization-wide enforcement with org-wide telemetry and compliance evidence export. Ongoing operations owned by the named committee.
Evidence and audit
Every agent action Guard intercepts produces a local decision record: what was requested, what was approved or blocked, and what changed as a result. Guard Cloud aggregates these records into exportable evidence for audit and compliance review. Learn how evidence works.
Operational expectations
No AI agents run in production environments. Guard enforces on the developer machine, not in CI or prod.
No data leaves the organization without explicit consent. Guard Cloud telemetry is opt-in and redacted at the source.
Enforcement works offline. Cloud dashboards are for visibility, not for blocking.
The deployment review names an owner and defines exit criteria at each stage. No stage auto-advances.
Commercial path
Guard Local is free for individual developers. Guard Cloud adds shared policy, dashboards, and org-wide telemetry for a monthly subscription. Review plans or request a deployment review.
Frequently asked questions
What is HOL Guard for enterprises?
HOL Guard is a runtime security layer for AI coding agents. The enterprise path adds shared policy, org-wide telemetry, and a bounded deployment review so teams can adopt AI coding tools without ceding control over code, credentials, or infrastructure.
Does Guard require cloud access to enforce locally?
No. Guard Local runs entirely on the developer machine and enforces policy without any cloud dependency. Guard Cloud adds dashboards, shared policy, and org-wide telemetry on top of the local enforcement layer, but enforcement never depends on cloud connectivity.
Which AI coding agents are supported?
Guard supports 13 harnesses including Codex, Claude Code, GitHub Copilot CLI, Cursor, Gemini CLI, OpenCode, Hermes, OpenClaw, Antigravity, Kimi Code, Grok Build, Pi / Oh My Pi, and Z Code. See the full compatibility matrix for integration mode, event surfaces, and known limitations per adapter.
What does a deployment review include?
A deployment review covers your control boundary, developer workflow constraints, evidence and audit requirements, and deployment operations. It produces a bounded rollout plan with success criteria, an owner, and an exit decision for each stage.
Does Guard replace native controls or sandboxes?
No. Guard adds a pre-flight approval layer and decision trail on top of existing harness controls. It does not replace native sandboxing, IDE confirmation dialogs, or existing CI/CD pipelines. Guard complements them by intercepting actions the native flow would not block.
Ready for a deployment review?
The review produces a bounded rollout plan with success criteria, a named owner, and an exit decision at each stage. You will need a defined control boundary, a list of harnesses in use, and a committee member who can sign off.
Request a deployment review