Secure local agents

Use the agent on your machine without copying broad company credentials into it.

Connect Codex CLI, Claude Code, OpenCode, or another MCP-compatible local agent to ExecWarden-scoped capabilities.

Where ExecWarden applies

How this boundary works in practice.

The local agent can still use local files and shell according to the machine boundary. GitHub, MCP tools, package actions, and internal APIs exposed through ExecWarden pass through Agent identity, grants, approvals, and the activity log.

Local loop

Keep the developer workflow intact.

The agent can run where the developer already works while ExecWarden mediates the external tools it provides.

Scoped credential

Use a session-specific MCP credential.

Give the local client a scoped Agent identity instead of handing it the underlying GitHub, SaaS, or internal API credentials.

Clear limit

Do not confuse local authority with governed authority.

Files, shell, network, and secrets independently available on the machine remain controlled by that environment.

Examples

Example tasks and outcomes.

1Local Codex reads the granted repositories and asks before opening a PR.
2Claude Code uses ExecWarden MCP for a scoped tool set.
3A developer revokes the Agent identity after the task is done.

Get started during beta

Start with one bounded task and one boundary to review.

Use the app during beta, or open the docs and choose the first agent task you want to govern.

Connect an MCP clientRead MCP quickstart