Stop risky agent actions before execution
Guard Local intercepts the next agent action and blocks, asks, or allows it against policy before any side effect is created.
HOL Guard for enterprise
Guard Local enforces policy on every developer machine, even offline. Guard Cloud adds shared policy, org-wide visibility, and deployment review without making enforcement cloud-dependent.
Download the enterprise briefAudit receipt
decision.saved · sha256
Redacted evidence exported without source or secret material.
Verified coverage
13 supported agents
Codex, Claude Code, Cursor, Gemini CLI, OpenCode, and more.
Open-source status
Guard Local · Apache-2.0
The local enforcement layer is inspectable and self-serve.
Visible result
Blocked before execution
Decision, reason, and next action shown together.
Evidence posture
Redacted decision records
Shared evidence omits source and secret material.
Supported AI coding agents
One control layer across the supported agent ecosystem.
System architecture
Guard Local sits between every agent action and the operating system. Shared policy, evidence, and deployment review are optional layers around that protected boundary.
Developer Machine
Code, credentials, and infrastructure
AI coding agents
13+ supported harnesses
HOL Guard Local
Intercept · block · ask · save decision
Protected machine resources / actions
File system, shell, network, secrets
Guard Cloud
Shared policy & org-wide telemetry
Security team workflows
Dashboards and trend analysis.
SIEM
Route redacted decision records.
Deployment review
Bounded rollout with named owners.
Your code stays local. · Your secrets stay local. · Enforcement stays local.
Three core outcomes
Guard Local intercepts the next agent action and blocks, asks, or allows it against policy before any side effect is created.
One policy layer governs 13 supported AI coding agents, so the same decision surface applies no matter which harness the team adopts.
Every decision leaves a redacted, reviewable record — so security can audit what happened without source or secret material leaving the machine.
decision.saved · sha256
REDACTED · source omitted
Enterprise controls
Identity, evidence, threat context, support, and deployment boundaries each get a deliberate place in the rollout.
Connect Guard workspaces to the identity system your security team already governs, with role-aware access to policy and evidence.
Identity provider
Team directory
SSO / SAML
Role mapping
Guard workspace
Policy access
Route redacted decision records into the log pipeline that already holds your security evidence.
12:04:18ALLOWpolicy.check · workspace
12:04:21BLOCKcommand.review · redacted
12:04:21RECEIPTdecision.saved · sha256
Bring the signals that matter to your environment into the same policy decision surface.
Scale the rollout with a commercial path and a clear support relationship.
Named
owner
Bounded
review
Ready
next step
Keep the shared control plane inside the network and operating boundary your team chooses.
Deployment boundary
Keep the shared layer inside the operating boundary your security team approves.
A bounded path to rollout
Keep the first step small, make the local boundary visible, and decide on broader rollout only after the team has a reviewable record of how Guard behaves.
Choose the initial harnesses, owners, and action boundary for a controlled evaluation.
Install Guard Local on the selected machines and observe policy decisions before actions run.
Review the decision trail, align with the named owner, and expand the boundary when it is ready.
HOL Guard is a runtime security layer for AI coding agents. The enterprise path adds shared policy, org-wide telemetry, and a bounded deployment review so teams can adopt AI coding tools without ceding control over code, credentials, or infrastructure.
No. Guard Local runs entirely on the developer machine and enforces policy without any cloud dependency. Guard Cloud adds dashboards, shared policy, and org-wide telemetry on top of the local enforcement layer, but enforcement never depends on cloud connectivity.
Guard supports 13 harnesses including Codex, Claude Code, OpenCode, Copilot, Cursor, Gemini, Hermes, OpenClaw, Antigravity, Kimi, Grok, Pi, and ZCode.
A deployment review covers your control boundary, developer workflow constraints, evidence and audit requirements, and deployment operations. It produces a bounded rollout plan with success criteria, an owner, and an exit decision for each stage.
Guard Cloud provides centralized policy management so teams share definitions. Individual developers still enforce locally with Guard Local, so enforcement never depends on cloud connectivity.
Guard Local collects minimal telemetry (session hashes, timing, policy decisions). Guard Cloud adds org-wide dashboards and trend analysis. All data is configurable per policy.
Yes. Guard Local operates fully offline with no cloud dependency. Guard Cloud is an optional add-on for teams that want dashboards and shared policy.
Walk through the local enforcement boundary, shared evidence posture, and deployment review path with the HOL Guard team.
Book a 20-minute security review