Contain and govern
every agent.

Jozu Agent Guard's Agent Enclave contains each agent in a dedicated microVM with its own kernel and policy engine. It can run on an engineer's laptop or on a node in your Kubernetes cluster, can only access what you choose to share, and works in air-gapped, private, or disconnected environments.


THE PROBLEM

The agent threat surface has expanded.

Can you verify what's running?

Models, agents, and MCP servers are sourced from third-party registries and your AI supply chain stops where it matters most, the runtime. Poisoned weights and swapped MCPs load exactly like the version that passed review, because nothing verifies that what you intended to run is in fact what is running.

Can you contain the damage?

An approved agent still reaches the whole machine: the files, the credentials, the network, and the other agents beside it. Approval happened once, before the agent existed in memory. What it does for the rest of the session, and whether it follows your policy, goes ungoverned.

Can you prove what happened?

When asked which agent version made a decision, which tools it called, and what data left with it, the answer is spread across shell history, vendor dashboards, and team chats with multiple gaps. Agent actions leave no standard trail, so there is nothing to hand an auditor and nothing to reconstruct an incident from.


VERIFY

Every decision logged and tracked.

Agent Guard writes every policy decision, artifact load, tool call, and prompt exchange it can see into one tamper-evident, cryptographically chained log. What was allowed, what was blocked and under which policy, and what was redacted before it left.

One log, not four.

The AI supply chain and the runtime land in the same record, so a blocked tool call and the scan that cleared the artifact it was reaching for sit next to each other instead of in two systems you have to join by hand.

Chained, to eliminate tampering.

Each entry is cryptographically chained to the one before it. Editing or removing an entry after the fact breaks the chain, which is the difference between a log and evidence.

Local logging, for full integrity.

A disconnected laptop is not a gap in the record. Agent Guard logs locally while it is offline and syncs to Jozu Hub when it reconnects, with the same structure either way.

An Agent Guard audit log filtered by allowed, blocked and redacted, showing entries across three days: a git.push tool call allowed, a git.push to main blocked under the pr-required policy, a security report completed with two critical and one high finding, a ModelKit moved between two digests, and an http.post tool call redacted

CONTAIN

Isolate agents on the laptop or in the cluster.

One agent, one microVM, one policy engine beside it. The only question is where those microVMs run and how many of them there are.

Endpoint devices · macOS

On your machine

Your engineers are already running Claude Code, Cursor, Codex and custom agents in YOLO mode. Agent Enclave secures the agent inside a microVM limiting access to approved files, tools, and credentials. The agents need no modification, no Docker prerequisite, and it installs as a single download.

  • The agent only sees the workspace you mount, and your home directory, SSH keys, and browser sessions stay out of it by default.
  • Tool calls and network access are checked before they run, and your policy decides whether to enforce, ask a human, or audit.
  • Agents that go rogue can't escape the VM, and a kill switch can instantly block all network egress.
For teams and production · Linux Kubernetes nodes

On Kubernetes

Agent Enclave runs on your Kubernetes cluster in its own microVM, with its own kernel. Policies have fine-grained controls: approve an MCP server while blocking a specific MCP or harness tool. Agents that go rogue can't escape the VM, and a kill switch can instantly block all network egress.

  • Works with any agent and any harness, even custom agents.
  • Agents, MCP servers, and policies arrive from Jozu Hub as signed, SHA-verified OCI artifacts, and policies prevent starting unapproved or dangerous artifacts.
  • Every decision from every agent lands in a chained audit log that syncs back to Jozu Hub.
Agent Enclave contains the agent and everything it does inside the VM, but it does not see the AI traffic leaving the browser tabs and desktop applications outside it. That is the job Policy Gateway does.

ENFORCE

Turn written policy into fully enforced guardrails.

What an agent can do inside its enclave is determined by the policy you define, not settings buried in a console. Agent Guard policies are written in YAML with CEL assertions then versioned and signed like any other artifact. They are reviewed the way you review code, and enforced on the machine rather than asked for over the network.

Tool specific policies.

A rule names the tools it applies to, so Bash and run_shell_command are covered by one rule whichever agent or harness reaches for them.

Easy escalations.

Some actions are legitimate often enough that blocking them is wrong and allowing them silently is worse. An elicit action stops the action and puts the decision in front of a person, with the reason attached.

Zero gray areas.

Conditions are CEL, so a rule says exactly what it catches, like a recursive delete or a destructive SQL statement, rather than approximating it with a name match.

A ToolPolicy YAML file named z1-destructive-data-operations that matches the Bash and run_shell_command tools, sets its action to Elicit, and carries CEL rules for confirming a recursive delete and a destructive SQL statement

MANAGE

Enforcement designed for enterprise scale.

An enclave on a laptop is easy to reason about. Six hundred of them across laptops and cluster nodes is a different problem, and it is the one that enterprises face. Jozu's Fleet Manager is where you administer and keep track of all your devices running Agent Guard.

What is running, and on what.

Every instance reports the Agent Guard version it is on, the agent definition inside it, and whether it is connected right now.

Which policy each one is actually enforcing.

Policies are versioned artifacts, so Fleet View shows the version applied to each enclave rather than the version you published.

What the agent has access to.

For enclaves you also see the MCP servers loaded in and live CPU, memory, and latency, so a stalled or blocked agent is visible without opening the machine it runs on.

Agent Guard Fleet Manager listing 612 instances, each with its host, agent activity, version and runtime, with one blocked instance highlighted, and a detail panel showing the selected instance's agent definition, 24 hour CPU, memory and latency trends, and connected MCP servers

NEXT STEP

Most of your AI use never touches an agent you run.

Agent Enclave contains the agents you run. Policy Gateway governs everything else, the browser tabs, the desktop applications, and the API calls that carry your data out without an agent anywhere in the picture.

Run agents inside walls they can't cross

Agent Enclave is one of the four places Agent Guard enforces your policy. Same engine, same policy language, same chained audit log as everywhere else it runs.