HOL Guard features

Stop risky agent actions before they execute

Guard sits between your AI coding agents and consequential actions. Shell, file, MCP, skill, and package calls are intercepted, evaluated against your policy, and routed for human review before any side effect occurs.

Shell commandsInspected before exec
MCP callsIntercepted at runtime
Package installsBlocked by default
Blocked before it ran

Blocked: action stopped

Paused action

OpenCode wants to run a destructive command

From OpenCode

Blocked

What Guard paused

Requests a sensitive native tool action: destructive shell command.

Command
Command
rm -rf /

Risk detected

1 of 2

Executing rm -rf / would delete the entire filesystem.

Product preview

Every component below is the real Guard product in read-only demo mode. Scroll to explore each surface.

Runtime protection

See every agent, machine, and connection

Guard intercepts agent launches before the first tool call. The live topology maps every machine, harness, MCP, skill, and repository. Risk stays visible at a glance.

  • Launch interception
  • Live topology graph
  • Machine and harness grouping
  • Agent and MCP inventory
  • Action controls
  • Local enforcement
Agents supported
13+
Interception layer
Kernel-level
Policy routing

Visual workflow builder for policy routing

Route each action to block, review, warn, or allow. Trace the exact policy path from launch to decision, then layer project and team overrides without losing precedence.

  • Block, review, warn, allow
  • Visual policy canvas
  • Decision flow tracing
  • Per-project overrides
Enforcement modes
4 tiers
Policy layers
Machine to team
Review workbench

Live queue of blocked actions

Blocked actions arrive with request context, a recommended action, and linked evidence. Review one or many, then export the signed decision trail.

  • Decision memory
  • Shared review assignment
  • Bulk approve and deny
  • CSV export for audit
Decision context
Full payload
Export format
CSV + JSON

Compare Guard with AI security vendors

Compare the control boundary, not a marketing checklist. Every status below is tied to first-party documentation accessed 2026-07-14.

Execution boundary
Before the tool runs
Operating model
Local-first control
Decision proof
Signed evidence per action
Open the evidence-backed vendor matrixDocumented, partially documented, and not publicly documented
DocumentedCapability described in first-party documentation.
PartialCapability partially documented; details incomplete at cited sources.
Not publicly documentedNot described in cited first-party sources.

HOL Guard versus Palo Alto Prisma AIRS comparison

CapabilityHOL GuardPrisma AIRS
Runtime action interception
Documented
Intercepts shell, file, MCP, skill, and package actions before execution.
Documented
API Intercept screens agent requests and responses before execution.
Policy enforcement
Documented
Local and team policy decides allow, narrow, or block per action.
Not documented
Policy enforcement model not detailed at cited sources.
Human review workflow
Documented
Dedicated review workbench with queue, decision controls, and routing.
Not documented
Dedicated human review workflow not documented at cited sources.
MCP and tool coverage
Documented
Screens MCP, shell, file, package, and skill surfaces.
Partial
Agent protection via API Intercept documented; MCP-specific coverage not detailed.
Routing and failover
Documented
Primary and failover route lanes with health monitoring and decision preview.
Not documented
Routing or failover model not documented at cited sources.
Evidence and audit
Documented
Signed receipts, evidence timeline, and decision replay retained locally.
Partial
API reference and agent discovery documented; receipt or audit model not detailed.
Deployment model
Documented
Local-first on macOS, Linux, and Windows; optional Cloud sync.
Documented
Cloud-based API Intercept.

Public documentation gaps reflect the cited sources only and do not indicate a product lacks a capability. Vendors may document features elsewhere or offer them privately. This comparison makes no pricing or superiority claims.

Plans

Start with local enforcement for free. Add sync, alerts, shared policy, and team evidence when you need them.

MonthlyAnnual
Feature
Pro
$15/mo
Local protection
Local protection modules
Cloud-connected devices5
Cloud approval and receipt sync
Module settings across Cloud devices
Cloud retention180 days
Included cloud storage5 GB
Weekly personal security digest
Matched critical advisories
Real-time activity alerts
Policy versioning and rollback
Advanced search and full evidence
Searchable module decision history
Organization module policy
Shared policy and team workflows
Choose a planStart Free Trial
Decision memory

Guard learns from your review decisions

Guard turns recurring review decisions into proposed memory rules with risk and scope attached. Nothing changes until you confirm the suggestion.

  • Auto-suggested rules from review patterns
  • Risk classification per suggestion
  • Scope selection: machine to team
  • One-time approval boundary
  • Cross-device memory sync
Scope options
4 levels
Confirmation
Always required
Evidence

Cryptographic proof for every decision

Every decision produces a signed, tamper-evident record containing the request, policy evaluation, and outcome. Export a verifiable bundle for audit or incident review.

  • Tamper-evident evidence chain
  • Full request payload capture
  • Cryptographic signatures
  • Exportable evidence bundles
Chain type
Tamper-evident
Export
Bundle + JSON
Supply chain

Cloud Firewall for MCP, skills, and packages

Inspect MCP servers, skills, and packages before they reach an agent. New entries default to deny until policy or a reviewer explicitly allows them.

  • MCP server inspection
  • Skill definition scanning
  • Package registry checks
  • Default-deny for new entries
Default stance
Deny new
Inspection
MCP + skills + npm
Policy and memory

Turn reviewed activity into policy

Layer machine, project, workspace, and team policy with predictable precedence. Shared memory keeps enforcement aligned across devices, even through a cloud outage.

  • Policy suggestions from review history
  • Layered scope: machine to team
  • Shared policy memory
  • Cross-device sync
  • Cloud outage independence
Layer precedence
Most specific wins
Sync
Cross-device

Capabilities

Every Guard capability, grouped by surface. Filter by plan, surface, or search to compare.

33 of 33 capabilities

Runtime interception

4 capabilities

Launch interception and wrappers

Installs supported harness launchers and wrappers so Guard can evaluate actions before they run.

LocalProTeam
Claude CodeCodex CLICursorOpenCodeGemini CLIGoose

Action controls

Checks supported shell, file, MCP, skill, prompt-sensitive, and package actions before side effects.

LocalProTeam
ShellFilesMCPSkillsPromptsPackages

Safe Decode

Inspects supported encoded command content without executing it.

LocalProTeam
Encoded shell content

Cloud-outage independence

Continues local policy checks when Guard Cloud is unavailable.

LocalProTeam
Local enforcement

Policy and enforcement

5 capabilities

Local policy and project overrides

Applies machine policy with project-level overrides for supported agent actions.

LocalProTeam
Machine policyProject policy

Local blocking and warnings

Blocks denied actions and warns when policy requires a human decision.

LocalProTeam
BlockWarnApproval

Policy integrity tooling

Detects and repairs supported policy integrity problems on the local machine.

LocalProTeam
Policy verificationPolicy repair

Policy suggestions

Turns reviewed activity into suggested policy updates for an operator to accept or reject.

ProTeam
Policy review

Shared policy memory

Shares reviewed policy decisions across authorized workspace members.

Team
Workspace policyDecision memory

Review and decisions

2 capabilities

Decision memory

Reuses scoped approval decisions across connected Guard sessions.

ProTeam
ApprovalsDecision scopes

Shared review and assignment

Lets teams review and assign Guard requests in a shared workflow.

Team
Review queueAssignments

Evidence and history

7 capabilities

Receipts, explain output, and approval center

Keeps local receipts and exposes policy explanations and pending approvals.

LocalProTeam
ReceiptsExplainApproval center

Cross-session and cross-device history

Brings synchronized Guard activity together across connected sessions and machines.

ProTeam
SessionsMachines

Searchable activity

Searches synchronized action and decision evidence in Guard Cloud.

ProTeam
Action historyDecision history

Incident summaries

Groups relevant Guard evidence into incident summaries for investigation.

ProTeam
Incidents

Evidence exports

Exports synchronized Guard activity for offline review and retention workflows.

ProTeam
ActivityAudit evidence

Shareable records

Creates controlled records that teammates can use during review and response.

ProTeam
Evidence records

Cases and audit history

Maintains team cases and an auditable history of supported administrative and review actions.

Team
CasesAudit history

Supply-chain protection

2 capabilities

MCP and Skill drift visibility

Shows changes to connected MCP servers and skills so operators can review drift.

ProTeam
MCP serversSkills

Cloud Firewall UI

Reviews supported MCP, skill, and package changes in the Guard Cloud firewall.

ProTeam
MCPSkillsPackages

Fleet controls and administration

7 capabilities

Machine pairing

Connects a local Guard installation to Guard Cloud with a short-lived pairing flow.

ProTeam
Interactive machines

Headless pairing

Connects supported remote and automated machines without an interactive browser on the host.

ProTeam
Remote hostsCI runners

Workspaces and roles

Organizes Guard resources in workspaces with role-based access.

Team
WorkspacesRoles

Service principals

Provides non-human workspace identities for supported automation.

Team
AutomationAPI access

Resource ownership

Assigns accountable owners to supported Guard resources.

Team
MachinesPoliciesCases

Team billing and limits

Manages workspace billing and plan limits for Guard Cloud teams.

Team
BillingUsage limits

Team administration and exports

Provides workspace administration and supported team-level exports.

Team
AdministrationExports

Integrations

6 capabilities

Digests and notifications

Sends Guard activity digests and supported operational notifications.

ProTeam
DigestNotification

Slack integration

Routes supported Guard notifications and review actions through Slack.

Team
Slack

GitHub integration

Connects supported Guard review and evidence workflows with GitHub.

Team
GitHub

Jira integration

Connects supported Guard case and review workflows with Jira.

Team
Jira

PagerDuty integration

Routes supported Guard incidents into PagerDuty response workflows.

Team
PagerDuty

Email and webhook integrations

Delivers supported Guard notifications through email and outbound webhooks.

Team
EmailWebhooks

Compatibility

Guard installs on macOS, Linux, and Windows and supports the AI coding agents below.

Platforms

macOSLinuxWindows

Supported AI coding agents

Codex
Claude Code
OpenCode
Copilot CLI
Cursor
Gemini CLI
Hermes
OpenClaw
Antigravity
Kimi
Grok
Pi
Z Code

Security model

Guard is local-first. Policy enforcement, evidence, and review happen on your machine. Cloud sync is optional.

Local-first enforcement

Policy checks run on your machine. Guard Cloud adds sync and team operations, but local enforcement works without it.

Action-level interception

Guard evaluates shell, file, MCP, skill, prompt-sensitive, and package actions before side effects occur.

Auditable evidence

Receipts, explanations, and approval decisions are captured locally and can be synchronized to Guard Cloud.

No forced upgrades

Local Guard is useful on its own. Cloud tiers add capabilities without degrading the local experience.

Risk-report privacy

Raw self-assessment answers are retained for up to 90 days. Private report links expire after 30 days. Report delivery does not opt you into marketing.

PrivacyTerms

Frequently asked questions

Guard uses harness-specific hooks, proxies, and managed runtime boundaries. On supported surfaces, policy can allow, observe, ask for approval, or block an action before execution. Coverage and fallback behavior are published per harness rather than claimed universally.

Local Guard controls can run without Guard Cloud. Cloud synchronization, shared team policy, remote intelligence, and other online features are separate capabilities and require connectivity when enabled.

Guard publishes release-specific compatibility only while the support snapshot is current. Supported and partial harnesses are listed in the compatibility section and harness security guides; coverage is event-specific. Devin is not currently verified as supported because no Devin adapter exists in the pinned stable or 3.0 alpha contract.

Both controls exist, but they are distinct. Guard can scan packages, skills, plugins, and MCP configuration for supply-chain risk, and it can also enforce policy before supported runtime actions. A scan result is not the same thing as runtime interception.

No. Guard uses policy-driven allow, observe, ask, block, and explicit unsupported outcomes. Approval delivery depends on the harness and event surface.

HOL Guard focuses on AI-agent artifacts and supported agent action boundaries. It complements rather than replaces EDR, endpoint antivirus, software composition analysis, dependency scanning, or general secrets-management controls.

More questions? Read the Guard documentation or run the self-assessment.

HOL Guard provides runtime interception of shell commands, secret reads, and MCP server changes before AI coding agents execute them. It supports Codex, Claude Code, Cursor, Gemini CLI, and OpenCode. Key capabilities include pre-action approval, audit receipts, policy enforcement, and optional cloud sync for teams. See the benchmark resultsfor how Guard compares to native controls across five harnesses.