Claude logoClaudeby Anthropic
Govern · Claude

Claude, governed at the paste and at the connector.

Claude for Enterprise connects to Google Drive, Slack, Jira, Confluence and GitHub through MCP, adds custom connectors to internal tools, and holds company context in Projects. BrowserShield stops company data at the paste. The MCP Gateway decides every connector call that reaches your systems. Your people keep Claude.

Enforced on the browserBrowserShieldearly accessCompany data stopped at the paste. Employees keep their tools. Only the leak stops.
0
sensitive pastes through, at the paste
<30ms
per-call verdict at the MCP Gateway
1:1
a named owner behind every custom connector
1
policy across every Claude account in use

How Agen governs Claude

  • BrowserShield recognises API keys, credentials and sensitive data as they are pasted or uploaded into Claude and blocks the paste. The rest of the session continues, and the person sees why.
  • Every Claude surface in use, the enterprise organisation, personal accounts and custom connectors, becomes visible in the Agen.co console with the person behind each one.
  • Custom MCP connectors to your internal tools route through the MCP Gateway, where every tool call is decided in-line against the identity behind it, in under 30ms, and the tokens never sit in a user's account.
  • Every custom connector gets a named owner. Above-policy calls pause for that owner, and the record shows who decided.
  • Enterprise SSO, SCIM, audit logs and retention settings stay as configured. Agen adds the verdict at the paste and at the gateway, and the record of both.
What Claude reaches

An assistant with a growing list of doors.

In an enterprise plan, Claude is connected to the systems your people work in. Each connector is a door, and custom connectors mean the list is open-ended.

Connectors over MCP
Google Drive, Gmail, Calendar, Slack, Jira, Confluence, GitHub, Notion, Asana and more, read and in many cases written with the connecting user's permissions.
Custom connectors
Any internal MCP server an admin or a user adds, exposing internal tools and data to the assistant.
Claude in Chrome
Browses, fills forms and completes tasks on websites where the person is signed in.
Projects and memory
Persists documents, instructions and context across conversations for a team, including anything sensitive that was added.
Artifacts and code execution
Writes and runs code, produces files, and analyses uploaded data in a sandbox.
Uploads and pastes
Anything a person pastes or uploads becomes model context: contracts, customer records, source code, keys.
Where the native controls stop

Admin settings govern the organisation. Not the paste, and not the call.

Claude's enterprise controls are the right controls to keep. They cannot see what a person pastes, and they cannot judge what a custom connector does to your systems.

01

The paste is the leak

Company data pasted into any AI tool leaves no trace in any log. Organisation policy sees a seat, not a paste. Blocking claude.ai at the proxy moves the paste to a phone.

visibility at the pastenone
02

Custom connectors are doors nobody catalogued

An MCP server added by a team is an integration with no registry entry, no owner and no review. Each one widens what a single prompt can reach into your systems.

blast radiusgrows per connector
03

Connectors act as the person, with no per-call owner

A connector call runs on the user's authorisation. The audit log shows a user and a connector, not who is accountable for what the call did.

accountable owner per callnone
04

Audit logs record usage, not verdicts

You can see who used Claude and which connector. You cannot show an auditor which pastes were stopped, which calls were judged, against which policy, and what was decided.

per-action verdict lognone
How Agen governs it

Stop the leak in the browser. Decide the call at the gateway.

The gateway decides. Shield enforces where the gateway cannot see. For Claude that means BrowserShield at the paste, and the MCP Gateway on every custom connector call that reaches your systems.

01 · Discover
See every Claude and every connector
BrowserShield surfaces every organisation and personal account in use. The gateway surfaces every custom MCP server and who attached it.
02 · Identify
Tie each paste and call to a person
Pastes resolve to the person from your IdP. Each custom connector becomes a governed principal with a named owner.
03 · Govern
Block the paste, judge the call
Keys and sensitive data are stopped at the paste. Custom connector calls reaching your systems are decided at the MCP Gateway per call, in under 30ms.
04 · Evidence
Record the chain
Every stopped paste and every gateway verdict logged with person, connector, target and decision. Exported to your SIEM. Produced at action time.
Shield

The gateway decides. Shield enforces where the gateway cannot see.

For Claude in the browser the leak is the paste, so BrowserShield does the work. AgenShield covers the Claude desktop app and Claude Code on managed devices with the same policy.

AS
On the device
AgenShield

Out-of-policy actions like touching production secrets or mass-deleting files are stopped before they execute. Everything else flows. Ships through your MDM.

AgenShield · Claude desktop · mbp-118blocked
Actionupload · contracts-q3.zip
Stoppedon device, before execution
Verdict26ms · logged
AgenShield in depth →
BS
In the browser
BrowserShield early access
Primary for Claude

Keys and sensitive data are recognised as they are pasted into AI tools, and the paste is blocked. Employees keep their tools. Only the leak stops.

BrowserShield · claude.aipaste blocked
Detectedcloud credentials in paste
Everything elseflows normally
Verdictlogged · same audit chain
Join the early-access program →
Same policy · same identity · same verdictShield overviewHow the gateway decides
Governed actions

What Claude asks to do, and what policy says.

Illustrative verdicts for common Claude actions under a typical policy. Paste rows are BrowserShield. Connector rows are the MCP Gateway.

Typical per-action verdicts for Claude
Claude actionVerdictWhy
Ask a question with no company data in the promptallowNothing sensitive in the paste. The tool in use is recorded, the person keeps working.
Paste an API key or access token into a promptdenyRecognised at the paste and blocked before it leaves the tab. The person sees why.
Upload a customer export containing personal datadenyRecognised at the upload and blocked. The person is pointed to a governed path.
Use a personal Claude account with company datadenyOutside the governed organisation. Blocked at the paste, the person is pointed to the enterprise account.
Custom connector reads an internal wiki through the gatewayallowScoped to the person's entitlement. Logged, not interrupted.
Custom connector queries a customer databasemaskThe query runs. Personal data is masked at the gateway before it enters the model context.
Custom connector writes to a production systemstep-upThe connector's named owner confirms from their phone. Approved, policy remembers.
A team adds a custom MCP server not on the approved listhuman-in-the-loopA new door. Reviewed once by the connector's owner, then policy remembers.

Verdicts are illustrative defaults. Every row is a policy you write once and Agen enforces per action, per identity.

Book a demo

See Claude governed, live.

Thirty minutes on the way your teams already use Claude. We show the verdict on each action, the named human behind the session, and the record it leaves. Bring your hardest question.

length30 minutes
formatlive, on your Claude setup
you seeevery action decided at runtime
Watch it happen

A credential heads for Claude. It never leaves the tab.

An engineer pastes a config block into claude.ai to ask a question. BrowserShield recognises cloud credentials in the paste and blocks it. The rest of the session continues.

blocked at the paste · live product scene
From connect to governing

Claude does not change. Neither does your organisation.

Your admin settings, SSO and connectors stay exactly as they are.

Day 1
Connect the MCP Gateway and your IdP
Custom connectors to your systems route through the gateway. Every call resolves to a person through Okta, Entra or any OIDC provider.
Day 1
Join BrowserShield early access
BrowserShield is running with design partners now. It deploys to managed browsers through the MDM you already have.
Week 1
Run observe-only
See which accounts and custom connectors are actually in use across the company before enforcing anything.
Week 2
Turn on the policies that matter
Start with secrets at the paste, personal accounts and connector writes. People only notice the crossing action.
The platform

Discover, Govern, Shield. One policy plane.

The same three capabilities govern Claude and every other agent you run, internal and external.

Expand a capability

Continuous discovery across your IdP, gateway, devices, cloud, and registries. Nothing has to self-register: agents are found, risk-scored, and resolved to a named human before they act.

  • Agentless and API-based across five surfaces
  • First-party, custom, and third-party agents alike
  • Every agent mapped to an owner, approver, and escalation
Agen Discover AI agent discovery flow: any identity provider, productivity suites and assistants, cloud, gateway, endpoints, and MCP server registries all feed one agent registry where every AI agent is inventoried, risk-scored on arrival, given a named human owner, and shadow AI is surfaced.
Discovery pulls from five surfaces into a single agent registry — no SDK self-registration required.
ClosesWhich agents are running that nobody registered?
no SDK required5 surfacesowner-mapped
Discover in depth →

FAQ

Questions, answered.

Does Agen replace Claude's enterprise admin controls?
No. Keep SSO, SCIM, connector settings and audit logs. They govern the organisation. Agen stops the leak at the paste, decides custom connector calls at the gateway, and records both.
Does this block people from using Claude?
No. Guardrails, not blanket blocks. People keep using Claude. Only the leaking paste or out-of-policy call stops, and the person sees why.
Can Agen govern Claude's built-in connectors to Drive or Slack?
Those reads happen between Anthropic's cloud and the source, so no browser or gateway sits in that path. Agen surfaces which connectors are attached and to whom. Per-call verdicts apply to custom connectors that reach your systems through the MCP Gateway.
Is Claude Code covered by this page?
Claude Code runs on developer machines and is governed on the device by AgenShield. It has its own page. This page covers the Claude assistant in the browser and its connectors.
Is BrowserShield generally available?
Early access. It is running with closed-beta design partners today. Ask about joining the program.

Govern Claude without taking it away.

Company data stopped at the paste, custom connectors decided at the gateway, a named person behind every one.