HOL Guard features
Stop risky agent actions before they execute
Guard sits between your AI coding agents and consequential actions. Shell, file, MCP, skill, and package calls are intercepted, evaluated against your policy, and routed for human review before any side effect occurs.
Blocked: action stopped
Paused action
OpenCode wants to run a destructive command
From OpenCode
What Guard paused
Requests a sensitive native tool action: destructive shell command.
rm -rf /
Risk detected
Executing rm -rf / would delete the entire filesystem.
Product preview
Every component below is the real Guard product in read-only demo mode. Scroll to explore each surface.
See every agent, machine, and connection
Guard intercepts agent launches before the first tool call. The live topology maps every machine, harness, MCP, skill, and repository. Risk stays visible at a glance.
- Launch interception
- Live topology graph
- Machine and harness grouping
- Agent and MCP inventory
- Action controls
- Local enforcement
- Agents supported
- 13+
- Interception layer
- Kernel-level
Visual workflow builder for policy routing
Route each action to block, review, warn, or allow. Trace the exact policy path from launch to decision, then layer project and team overrides without losing precedence.
- Block, review, warn, allow
- Visual policy canvas
- Decision flow tracing
- Per-project overrides
- Enforcement modes
- 4 tiers
- Policy layers
- Machine to team
Live queue of blocked actions
Blocked actions arrive with request context, a recommended action, and linked evidence. Review one or many, then export the signed decision trail.
- Decision memory
- Shared review assignment
- Bulk approve and deny
- CSV export for audit
- Decision context
- Full payload
- Export format
- CSV + JSON
Compare Guard with AI security vendors
Compare the control boundary, not a marketing checklist. Every status below is tied to first-party documentation accessed 2026-07-14.
- Execution boundary
- Before the tool runs
- Operating model
- Local-first control
- Decision proof
- Signed evidence per action
Open the evidence-backed vendor matrixDocumented, partially documented, and not publicly documented+
| Capability | HOL Guard | Prisma AIRS | Check Point | Lasso | Protect AI | HiddenLayer |
|---|---|---|---|---|---|---|
| Runtime action interception | Documented Intercepts shell, file, MCP, skill, and package actions before execution. | Documented API Intercept screens agent requests and responses before execution. | Partial Guard API screens requests at runtime; Agent Behavior Defense flags tool calls; action-level interception not documented. | Partial MCP Gateway secures interactions in production; action-level interception not documented. | Documented Runtime security detects and stops AI threats in production. | Partial Runtime protection for agentic systems documented; action-level interception not detailed. |
| Policy enforcement | Documented Local and team policy decides allow, narrow, or block per action. | Not documented Policy enforcement model not detailed at cited sources. | Documented Policy-based guardrails with configurable flagging sensitivity levels. | Not documented Policy enforcement model not detailed at cited source. | Not documented Policy enforcement model not detailed at cited source. | Not documented Policy enforcement model not detailed at cited sources. |
| Human review workflow | Documented Dedicated review workbench with queue, decision controls, and routing. | Not documented Dedicated human review workflow not documented at cited sources. | Not documented Dedicated human review workflow not documented at cited sources. | Not documented Dedicated human review workflow not documented at cited source. | Not documented Dedicated human review workflow not documented at cited source. | Not documented Dedicated human review workflow not documented at cited sources. |
| MCP and tool coverage | Documented Screens MCP, shell, file, package, and skill surfaces. | Partial Agent protection via API Intercept documented; MCP-specific coverage not detailed. | Partial Tool message roles, Tool Allow/Deny List, and tool description screening documented; full MCP server coverage not detailed. | Documented MCP Gateway secures Model Context Protocol interactions in production. | Not documented MCP or tool coverage not detailed at cited source. | Documented Agentic and MCP security solution documented. |
| Routing and failover | Documented Primary and failover route lanes with health monitoring and decision preview. | Not documented Routing or failover model not documented at cited sources. | Not documented Routing or failover model not documented at cited sources. | Not documented Routing or failover model not documented at cited source. | Not documented Routing or failover model not documented at cited source. | Not documented Routing or failover model not documented at cited sources. |
| Evidence and audit | Documented Signed receipts, evidence timeline, and decision replay retained locally. | Partial API reference and agent discovery documented; receipt or audit model not detailed. | Partial Results logging and SIEM export documented; receipt model not detailed. | Partial Compliance-ready audit trails mentioned; receipt model not detailed. | Partial Runtime visibility documented; audit trail model not detailed. | Partial Visibility for agentic systems documented; audit trail model not detailed. |
| Deployment model | Documented Local-first on macOS, Linux, and Windows; optional Cloud sync. | Documented Cloud-based API Intercept. | Documented SaaS or self-hosted deployment. | Partial SaaS platform with open-source MCP Gateway; deployment architecture partially detailed. | Partial SaaS runtime security; now part of Palo Alto Networks. | Partial SaaS platform; deployment architecture partially detailed. |
HOL Guard versus Palo Alto Prisma AIRS comparison
| Capability | HOL Guard | Prisma AIRS |
|---|---|---|
| Runtime action interception | Documented Intercepts shell, file, MCP, skill, and package actions before execution. | Documented API Intercept screens agent requests and responses before execution. |
| Policy enforcement | Documented Local and team policy decides allow, narrow, or block per action. | Not documented Policy enforcement model not detailed at cited sources. |
| Human review workflow | Documented Dedicated review workbench with queue, decision controls, and routing. | Not documented Dedicated human review workflow not documented at cited sources. |
| MCP and tool coverage | Documented Screens MCP, shell, file, package, and skill surfaces. | Partial Agent protection via API Intercept documented; MCP-specific coverage not detailed. |
| Routing and failover | Documented Primary and failover route lanes with health monitoring and decision preview. | Not documented Routing or failover model not documented at cited sources. |
| Evidence and audit | Documented Signed receipts, evidence timeline, and decision replay retained locally. | Partial API reference and agent discovery documented; receipt or audit model not detailed. |
| Deployment model | Documented Local-first on macOS, Linux, and Windows; optional Cloud sync. | Documented Cloud-based API Intercept. |
First-party sources
- HOL Guard
- Palo Alto Prisma AIRS
- Check Point AI Guardrails
- Lasso Security
- Protect AI Layer
- HiddenLayer
Public documentation gaps reflect the cited sources only and do not indicate a product lacks a capability. Vendors may document features elsewhere or offer them privately. This comparison makes no pricing or superiority claims.
Plans
Start with local enforcement for free. Add sync, alerts, shared policy, and team evidence when you need them.
| Feature | Free $0forever | Solo $4.99/mo | Pro $15/mo | Team $30/seat/mo |
|---|---|---|---|---|
| Local protection | ||||
| Local protection modules | ||||
| Cloud-connected devices | 2 | 5 | Up to 25 | |
| Cloud approval and receipt sync | ||||
| Module settings across Cloud devices | ||||
| Cloud retention | 30 days | 180 days | 365 days | |
| Included cloud storage | 1 GB | 5 GB | 25 GB + 5 GB/seat | |
| Weekly personal security digest | ||||
| Matched critical advisories | ||||
| Real-time activity alerts | ||||
| Policy versioning and rollback | ||||
| Advanced search and full evidence | ||||
| Searchable module decision history | ||||
| Organization module policy | ||||
| Shared policy and team workflows | ||||
| Choose a plan | Get Started | Keep my Guard memory | Start Free Trial | Start Team |
Guard learns from your review decisions
Guard turns recurring review decisions into proposed memory rules with risk and scope attached. Nothing changes until you confirm the suggestion.
- Auto-suggested rules from review patterns
- Risk classification per suggestion
- Scope selection: machine to team
- One-time approval boundary
- Cross-device memory sync
- Scope options
- 4 levels
- Confirmation
- Always required
Cryptographic proof for every decision
Every decision produces a signed, tamper-evident record containing the request, policy evaluation, and outcome. Export a verifiable bundle for audit or incident review.
- Tamper-evident evidence chain
- Full request payload capture
- Cryptographic signatures
- Exportable evidence bundles
- Chain type
- Tamper-evident
- Export
- Bundle + JSON
Cloud Firewall for MCP, skills, and packages
Inspect MCP servers, skills, and packages before they reach an agent. New entries default to deny until policy or a reviewer explicitly allows them.
- MCP server inspection
- Skill definition scanning
- Package registry checks
- Default-deny for new entries
- Default stance
- Deny new
- Inspection
- MCP + skills + npm
Turn reviewed activity into policy
Layer machine, project, workspace, and team policy with predictable precedence. Shared memory keeps enforcement aligned across devices, even through a cloud outage.
- Policy suggestions from review history
- Layered scope: machine to team
- Shared policy memory
- Cross-device sync
- Cloud outage independence
- Layer precedence
- Most specific wins
- Sync
- Cross-device
Capabilities
Every Guard capability, grouped by surface. Filter by plan, surface, or search to compare.
33 of 33 capabilities
Runtime interception
4 capabilities
+
Runtime interception
4 capabilities
Launch interception and wrappers
Installs supported harness launchers and wrappers so Guard can evaluate actions before they run.
Action controls
Checks supported shell, file, MCP, skill, prompt-sensitive, and package actions before side effects.
Safe Decode
Inspects supported encoded command content without executing it.
Cloud-outage independence
Continues local policy checks when Guard Cloud is unavailable.
Policy and enforcement
5 capabilities
+
Policy and enforcement
5 capabilities
Local policy and project overrides
Applies machine policy with project-level overrides for supported agent actions.
Local blocking and warnings
Blocks denied actions and warns when policy requires a human decision.
Policy integrity tooling
Detects and repairs supported policy integrity problems on the local machine.
Policy suggestions
Turns reviewed activity into suggested policy updates for an operator to accept or reject.
Shared policy memory
Shares reviewed policy decisions across authorized workspace members.
Review and decisions
2 capabilities
+
Review and decisions
2 capabilities
Decision memory
Reuses scoped approval decisions across connected Guard sessions.
Shared review and assignment
Lets teams review and assign Guard requests in a shared workflow.
Evidence and history
7 capabilities
+
Evidence and history
7 capabilities
Receipts, explain output, and approval center
Keeps local receipts and exposes policy explanations and pending approvals.
Cross-session and cross-device history
Brings synchronized Guard activity together across connected sessions and machines.
Searchable activity
Searches synchronized action and decision evidence in Guard Cloud.
Incident summaries
Groups relevant Guard evidence into incident summaries for investigation.
Evidence exports
Exports synchronized Guard activity for offline review and retention workflows.
Shareable records
Creates controlled records that teammates can use during review and response.
Cases and audit history
Maintains team cases and an auditable history of supported administrative and review actions.
Supply-chain protection
2 capabilities
+
Supply-chain protection
2 capabilities
MCP and Skill drift visibility
Shows changes to connected MCP servers and skills so operators can review drift.
Cloud Firewall UI
Reviews supported MCP, skill, and package changes in the Guard Cloud firewall.
Fleet controls and administration
7 capabilities
+
Fleet controls and administration
7 capabilities
Machine pairing
Connects a local Guard installation to Guard Cloud with a short-lived pairing flow.
Headless pairing
Connects supported remote and automated machines without an interactive browser on the host.
Workspaces and roles
Organizes Guard resources in workspaces with role-based access.
Service principals
Provides non-human workspace identities for supported automation.
Resource ownership
Assigns accountable owners to supported Guard resources.
Team billing and limits
Manages workspace billing and plan limits for Guard Cloud teams.
Team administration and exports
Provides workspace administration and supported team-level exports.
Integrations
6 capabilities
+
Integrations
6 capabilities
Digests and notifications
Sends Guard activity digests and supported operational notifications.
Slack integration
Routes supported Guard notifications and review actions through Slack.
GitHub integration
Connects supported Guard review and evidence workflows with GitHub.
Jira integration
Connects supported Guard case and review workflows with Jira.
PagerDuty integration
Routes supported Guard incidents into PagerDuty response workflows.
Email and webhook integrations
Delivers supported Guard notifications through email and outbound webhooks.
Compatibility
Guard installs on macOS, Linux, and Windows and supports the AI coding agents below.
Platforms
Supported AI coding agents
Security model
Guard is local-first. Policy enforcement, evidence, and review happen on your machine. Cloud sync is optional.
Local-first enforcement
Policy checks run on your machine. Guard Cloud adds sync and team operations, but local enforcement works without it.
Action-level interception
Guard evaluates shell, file, MCP, skill, prompt-sensitive, and package actions before side effects occur.
Auditable evidence
Receipts, explanations, and approval decisions are captured locally and can be synchronized to Guard Cloud.
No forced upgrades
Local Guard is useful on its own. Cloud tiers add capabilities without degrading the local experience.
Risk-report privacy
Raw self-assessment answers are retained for up to 90 days. Private report links expire after 30 days. Report delivery does not opt you into marketing.
Frequently asked questions
Guard uses harness-specific hooks, proxies, and managed runtime boundaries. On supported surfaces, policy can allow, observe, ask for approval, or block an action before execution. Coverage and fallback behavior are published per harness rather than claimed universally.
Local Guard controls can run without Guard Cloud. Cloud synchronization, shared team policy, remote intelligence, and other online features are separate capabilities and require connectivity when enabled.
Guard publishes release-specific compatibility only while the support snapshot is current. Supported and partial harnesses are listed in the compatibility section and harness security guides; coverage is event-specific. Devin is not currently verified as supported because no Devin adapter exists in the pinned stable or 3.0 alpha contract.
Both controls exist, but they are distinct. Guard can scan packages, skills, plugins, and MCP configuration for supply-chain risk, and it can also enforce policy before supported runtime actions. A scan result is not the same thing as runtime interception.
No. Guard uses policy-driven allow, observe, ask, block, and explicit unsupported outcomes. Approval delivery depends on the harness and event surface.
HOL Guard focuses on AI-agent artifacts and supported agent action boundaries. It complements rather than replaces EDR, endpoint antivirus, software composition analysis, dependency scanning, or general secrets-management controls.
More questions? Read the Guard documentation or run the self-assessment.
See also
Related surfaces for evaluating Guard across harnesses, teams, and plans.
- Harness compatibility matrixSee which AI coding agents Guard supports natively or through wrappers, with browser fallback and auto-resume details.
- Enterprise evaluationDeployment review, bounded trial evaluation, and team rollout for organizations adopting AI coding agents.
- Pricing plansCompare Free, Pro, and Team tiers — including policy enforcement, cloud sync, and dashboard features.
HOL Guard provides runtime interception of shell commands, secret reads, and MCP server changes before AI coding agents execute them. It supports Codex, Claude Code, Cursor, Gemini CLI, and OpenCode. Key capabilities include pre-action approval, audit receipts, policy enforcement, and optional cloud sync for teams. See the benchmark resultsfor how Guard compares to native controls across five harnesses.