Agent loop
The client or runtime owns the loop; ExecWarden owns the mediated capability boundary.
Authorized client

Integration shape
Agent loop
The client or runtime owns the loop; ExecWarden owns the mediated capability boundary.
Tools
Granted capabilities appear through MCP discovery and invocation.
Credentials
The client authenticates as an Agent identity with scoped access.
Governed actions
Tool discovery, invocation, approvals, expiry, and revocation follow the grants on that identity.
ExecWarden evidence
Mediated calls can appear in the activity log with related approval records.
Start
Create an Agent identity and configure the MCP client with its endpoint and credential.
One setup pattern
The same boundary can apply whether the caller is Codex CLI, Claude Code, OpenCode, a hosted session, or another MCP-compatible client.
Identity
An Agent identity gives the client a revocable, inspectable source instead of a vague user token.
Discovery
The client discovers capabilities according to the scoped grants attached to that identity.
Policy
Risky actions can pause for review no matter which compatible client initiated the call.
Examples
Get started during beta
Use the app during beta, or open the docs and choose the first agent task you want to govern.