Contain and govern
every agent.
Jozu Agent Guard's Agent Enclave contains each agent in a dedicated microVM with its own kernel and policy engine. It can run on an engineer's laptop or on a node in your Kubernetes cluster, can only access what you choose to share, and works in air-gapped, private, or disconnected environments.
The agent threat surface has expanded.
Can you verify what's running?
Models, agents, and MCP servers are sourced from third-party registries and your AI supply chain stops where it matters most, the runtime. Poisoned weights and swapped MCPs load exactly like the version that passed review, because nothing verifies that what you intended to run is in fact what is running.
Can you contain the damage?
An approved agent still reaches the whole machine: the files, the credentials, the network, and the other agents beside it. Approval happened once, before the agent existed in memory. What it does for the rest of the session, and whether it follows your policy, goes ungoverned.
Can you prove what happened?
When asked which agent version made a decision, which tools it called, and what data left with it, the answer is spread across shell history, vendor dashboards, and team chats with multiple gaps. Agent actions leave no standard trail, so there is nothing to hand an auditor and nothing to reconstruct an incident from.
Every decision logged and tracked.
Agent Guard writes every policy decision, artifact load, tool call, and prompt exchange it can see into one tamper-evident, cryptographically chained log. What was allowed, what was blocked and under which policy, and what was redacted before it left.
One log, not four.
The AI supply chain and the runtime land in the same record, so a blocked tool call and the scan that cleared the artifact it was reaching for sit next to each other instead of in two systems you have to join by hand.
Chained, to eliminate tampering.
Each entry is cryptographically chained to the one before it. Editing or removing an entry after the fact breaks the chain, which is the difference between a log and evidence.
Local logging, for full integrity.
A disconnected laptop is not a gap in the record. Agent Guard logs locally while it is offline and syncs to Jozu Hub when it reconnects, with the same structure either way.
Isolate agents on the laptop or in the cluster.
One agent, one microVM, one policy engine beside it. The only question is where those microVMs run and how many of them there are.
On your machine
Your engineers are already running Claude Code, Cursor, Codex and custom agents in YOLO mode. Agent Enclave secures the agent inside a microVM limiting access to approved files, tools, and credentials. The agents need no modification, no Docker prerequisite, and it installs as a single download.
- The agent only sees the workspace you mount, and your home directory, SSH keys, and browser sessions stay out of it by default.
- Tool calls and network access are checked before they run, and your policy decides whether to enforce, ask a human, or audit.
- Agents that go rogue can't escape the VM, and a kill switch can instantly block all network egress.
On Kubernetes
Agent Enclave runs on your Kubernetes cluster in its own microVM, with its own kernel. Policies have fine-grained controls: approve an MCP server while blocking a specific MCP or harness tool. Agents that go rogue can't escape the VM, and a kill switch can instantly block all network egress.
- Works with any agent and any harness, even custom agents.
- Agents, MCP servers, and policies arrive from Jozu Hub as signed, SHA-verified OCI artifacts, and policies prevent starting unapproved or dangerous artifacts.
- Every decision from every agent lands in a chained audit log that syncs back to Jozu Hub.
Turn written policy into fully enforced guardrails.
What an agent can do inside its enclave is determined by the policy you define, not settings buried in a console. Agent Guard policies are written in YAML with CEL assertions then versioned and signed like any other artifact. They are reviewed the way you review code, and enforced on the machine rather than asked for over the network.
Tool specific policies.
A rule names the tools it applies to, so Bash and run_shell_command are covered by one rule whichever agent or harness reaches for them.
Easy escalations.
Some actions are legitimate often enough that blocking them is wrong and allowing them silently is worse. An elicit action stops the action and puts the decision in front of a person, with the reason attached.
Zero gray areas.
Conditions are CEL, so a rule says exactly what it catches, like a recursive delete or a destructive SQL statement, rather than approximating it with a name match.
Enforcement designed for enterprise scale.
An enclave on a laptop is easy to reason about. Six hundred of them across laptops and cluster nodes is a different problem, and it is the one that enterprises face. Jozu's Fleet Manager is where you administer and keep track of all your devices running Agent Guard.
What is running, and on what.
Every instance reports the Agent Guard version it is on, the agent definition inside it, and whether it is connected right now.
Which policy each one is actually enforcing.
Policies are versioned artifacts, so Fleet View shows the version applied to each enclave rather than the version you published.
What the agent has access to.
For enclaves you also see the MCP servers loaded in and live CPU, memory, and latency, so a stalled or blocked agent is visible without opening the machine it runs on.
Most of your AI use never touches an agent you run.
Agent Enclave contains the agents you run. Policy Gateway governs everything else, the browser tabs, the desktop applications, and the API calls that carry your data out without an agent anywhere in the picture.
Run agents inside walls they can't cross
Agent Enclave is one of the four places Agent Guard enforces your policy. Same engine, same policy language, same chained audit log as everywhere else it runs.