| Where we built for depth |
| Can it stop a coding agent's own shell and file actions before they run? |
Yes Answers the Claude Code and Cursor PreToolUse hook with allow, ask, or deny. PostToolUse scans a document the agent just read for macros and injected text. By default a path outside the workspace is held for a person. |
Partly Agentic endpoint security arrived with the Koi acquisition in April 2026. Hook-level blocking is not described. |
Yes Native hooks for Claude Code, Cursor Enterprise, and GitHub Copilot. Policies ship in Detect mode; blocking is switched on per policy. |
Yes Lists agent hooks among its enforcement points, and discovers Claude Code, Cursor, and Codex on endpoints. |
Partly Tool calls that go through its MCP gateway. An agent's built-in shell and file tools are not described. |
Partly MCP traffic through its gateway. Built-in agent tools are not described. |
| Can the decision run with no vendor cloud in the path? |
Yes One Go binary on your machine. The self-test and the full walkthrough run offline. |
Partly A software firewall that can run on your own KVM hosts, alongside a managed service. |
Not found Delivered as a platform; homegrown agents call its Evaluate API. |
Not found |
Partly MCP Bridge runs in your own infrastructure, offered through Okta Professional Services. |
Partly The MIT-licensed gateway is self-hosted. Its advanced guardrail calls Lasso's API. |
| Does it name actions that went around it? |
Yes Compares what it allowed with the provider's own audit export and names each action it never saw. You supply the export. |
Not found |
Not found |
Not found |
Not found |
Not found |
| Can an outsider check a decision record without access to your systems? |
Yes Signed receipts, a standalone verifier, and verifiers in JavaScript and Python. Keep the signing key off the audit disk, or a local admin could re-sign a shortened log. |
Not found |
Not found |
Not found |
Not found |
Not found |
| Can delegated authority only narrow, and does revoking it cut off every child? |
Yes A child grant can't exceed its parent. Revoking walks the tree and signs a record of each grant it ends. Delegation across organizations verifies without a shared secret. |
Not found |
Not found |
Not found |
Partly Short-lived, task-scoped tokens that carry the delegation chain. Revoking at the gateway is planned for Q4 2026. |
Not found |
| Does it check a payment against what a person approved? |
Yes A swapped cart, a tainted cart, or an amount over the cap is refused. pay reverse closes only after a registered provider confirms the money is gone. The core binary ships no live Stripe or Adyen connector. It decides; your payment rail moves the money. |
Not found |
Not found |
Not found |
Not found |
Not found |
| Where they are ahead |
| Does it find agents across SaaS and cloud platforms? |
Partly Pulls or imports inventories from Microsoft Graph, Okta, and Amazon Bedrock, and scans laptops, including ungoverned local model ports. No Copilot Studio, Agentforce, or ServiceNow connector. |
Yes Agents, apps, and models across the environment. |
Yes SaaS, cloud agent platforms, and endpoints. |
Yes Cloud platforms, SaaS agent builders, endpoints, and code repositories. |
Yes A registry of agents with human owners, plus shadow agent discovery. |
Partly GenAI discovery and monitoring in the paid platform. |
| Does detection use trained models, not only patterns? |
No Injection scoring is pattern- and structure-based, so novel phrasing can pass. An optional local model helps the data classifier. |
Yes Its Precision AI engine. |
Yes Deterministic rules plus LLM-based intent detection, run asynchronously. |
Yes Its own AI security models. |
Not found Identity and policy, not content detection. |
Yes Through Lasso's detection API. |
| Is there an established company behind it? |
Early A young company with no public customers yet. Judge the build, and ask us about support terms. |
Yes |
Yes |
Yes |
Yes |
Yes |