Cursor logoCursorby Anysphere
Govern · Cursor

Cursor's agent, governed one action at a time.

Cursor's agent mode edits files, runs terminal commands and calls MCP servers from inside the editor, often with auto-run switched on. Background agents do the same from the cloud. Agen judges each action at runtime, against the developer behind it, and records the verdict. The team keeps Cursor.

Enforced on the endpointAgenShieldStopped on the device, before execution. The gateway's verdict, enforced where the gateway cannot see.
<30ms
per-action verdict at runtime
1:1
a named developer behind every agent run
0
changes to the editor or its rules
1 day
from install to governing

How Agen governs Cursor

  • AgenShield runs on the developer's machine and judges every file write, terminal command and MCP call Cursor's agent makes, before it executes, whether auto-run is on or off.
  • Background agents that act on your repositories from the cloud are governed where they touch your systems, tied to the developer who launched them.
  • Each action resolves to the developer's identity from your IdP. The agent acts as a governed principal, not as an editor process.
  • Policy returns a verdict in under 30ms: allow, mask, step up, hand to a human, or deny. Only the crossing action stops.
  • Cursor rules, the command allowlist and team settings stay in place. Agen adds the central verdict and the record.
What Cursor reaches

An editor that acts on the workspace, and beyond it.

Cursor's agent is the most used surface in the product. These are the things it can do on a machine with your developer's credentials.

Files across the workspace
Multi-file edits and refactors across the open project, and any path the developer can reach.
Terminal commands
Runs build, test, install and system commands. With auto-run enabled, no prompt is shown for commands outside the denylist.
MCP servers
Connects to internal tools, databases and ticketing systems exposed as MCP servers, configured per project or per user.
Background agents
Runs long tasks in cloud environments with repository access, opening pull requests when done.
Rules and context
Reads project rules, documentation and any file indexed for context, including ones nobody meant to share.
Web and browser tools
Fetches URLs and, with the right extensions, drives a browser during a task.
Where the native controls stop

Auto-run trusts the allowlist. Nobody else can see it.

Cursor's allowlist, denylist and team rules are useful, and engineering should keep them. They are configured on the machine by the person the agent acts for.

01

The allowlist is local

Which commands auto-run, which are denied and whether the agent can delete files are settings on each machine. Nothing central sees the configuration or the decisions it makes.

enforcement scopeone machine
02

The agent commits as the developer

Changes land under the developer's git identity and credentials. When something ships badly, the author field is a person's name, and nothing distinguishes their choice from the agent's.

author fielda person's name
03

Background agents run where the device is not

A background agent acts on your repository from a cloud environment. Endpoint tools cannot see it and the local allowlist does not apply.

visible to endpoint toolsno
04

No single place to write a rule or read a record

Team settings cover the editor, not the action. There is no central verdict, no per-action log outside the machine, and nothing to show an auditor.

central audit trailnone
How Agen governs it

Same editor, same rules. One verdict per action.

The gateway decides. Shield enforces where the gateway cannot see. AgenShield sits on the device, does not change how Cursor is used, and stops the crossing action before it executes. Background agents are decided at the gateway.

01 · Discover
Find every Cursor install and agent
Endpoint telemetry surfaces every machine running Cursor, every MCP server configured, and every background agent touching your repositories.
02 · Identify
Tie the agent to a developer
Agent runs resolve to the developer's identity from your IdP. Cursor becomes a governed principal with a named owner.
03 · Govern
Judge each action in-line
File writes, terminal commands and MCP calls are evaluated per action against policy and identity, before they execute. Verdict in under 30ms.
04 · Evidence
Record the chain
Every action and verdict logged with developer, project, command and decision. Exported to your SIEM.
Shield

The gateway decides. Shield enforces where the gateway cannot see.

Cursor's agent runs on the developer's machine, so AgenShield does the work: the gateway's verdict, enforced where the gateway cannot see. BrowserShield covers what the same developer pastes into AI tools in the browser. Background agents are decided at the gateway where they reach your repositories.

AS
On the device
AgenShield
Primary for Cursor

Out-of-policy actions like touching production secrets or mass-deleting files are stopped before they execute. Everything else flows. Ships through your MDM.

AgenShield · Cursor agent · dev-mbp-118blocked
Actionauto-run · cat ~/.ssh/id_rsa
Stoppedon device, before execution
Verdict26ms · logged
AgenShield in depth →
BS
In the browser
BrowserShield early access

Keys and sensitive data are recognised as they are pasted into AI tools, and the paste is blocked. Employees keep their tools. Only the leak stops.

BrowserShield · chatgpt.compaste blocked
Detectedworkspace secret in paste
Everything elseflows normally
Verdictlogged · same audit chain
Join the early-access program →
Same policy · same identity · same verdictShield overviewHow the gateway decides
Governed actions

What Cursor's agent asks to do, and what policy says.

Illustrative verdicts for common Cursor actions under a typical policy.

Typical per-action verdicts for Cursor
Cursor actionVerdictWhy
Multi-file edit inside the workspaceallowIn scope for the developer and the task. Logged, not interrupted.
Auto-run the test suiteallowNormal engineering work on the developer's own machine.
Auto-run a command that touches ~/.ssh or cloud credentialsdenyA credential has no place in an agent's context. Blocked before it executes, whatever the allowlist says.
Delete files outside the workspacedenyOutside task scope on a device with the developer's privileges.
Background agent opens a pull request to a protected branchhuman-in-the-loopThe launching developer reviews before the change reaches the branch.
Query a customer database through an MCP servermaskThe query runs. Personal data is masked before it enters the model context.
Add an MCP server not on the approved liststep-upA new door. The developer confirms it once, and the record shows who opened it.
Send workspace contents to an external URLdenyRecognised at the point of exfiltration and blocked in-line.

Verdicts are illustrative defaults. Every row is a policy you write once and Agen enforces per action, per identity.

Book a demo

See Cursor governed, live.

Thirty minutes on the way your teams already use Cursor. We show the verdict on each action, the named human behind the session, and the record it leaves. Bring your hardest question.

length30 minutes
formatlive, on your Cursor setup
you seeevery action decided at runtime
Watch it happen

Cursor's agent reaches for a secret. On a laptop.

It never crosses your network controls, and no log outside that machine would record the attempt. AgenShield stops it on the device.

on-device block · live product scene
From install to governing

Rolled out like software. The editor does not change.

Cursor stays exactly as your engineers use it today.

Day 1
Ship AgenShield through your MDM
The endpoint agent deploys to developer machines with the tooling you already use. No editor extension to install.
Day 1
Connect your IdP
Agent runs resolve to developers through Okta, Entra or any OIDC provider.
Week 1
Run observe-only
See every agent action across the fleet, including auto-run commands and MCP servers in use, before enforcing anything.
Week 2
Turn on the policies that matter
Start with credentials, deletes and protected branches. Developers only notice the crossing action.
The platform

Discover, Govern, Shield. One policy plane.

The same three capabilities govern Cursor and every other agent you run, internal and external.

Expand a capability

Continuous discovery across your IdP, gateway, devices, cloud, and registries. Nothing has to self-register: agents are found, risk-scored, and resolved to a named human before they act.

  • Agentless and API-based across five surfaces
  • First-party, custom, and third-party agents alike
  • Every agent mapped to an owner, approver, and escalation
Agen Discover AI agent discovery flow: any identity provider, productivity suites and assistants, cloud, gateway, endpoints, and MCP server registries all feed one agent registry where every AI agent is inventoried, risk-scored on arrival, given a named human owner, and shadow AI is surfaced.
Discovery pulls from five surfaces into a single agent registry — no SDK self-registration required.
ClosesWhich agents are running that nobody registered?
no SDK required5 surfacesowner-mapped
Discover in depth →

FAQ

Questions, answered.

Does Agen replace Cursor's command allowlist and team rules?
No. Engineering keeps the allowlist, denylist, rules and team settings. Agen adds a central verdict on each action, anchored to the developer's identity, and a record outside the machine.
What happens when auto-run is enabled?
Nothing changes for the developer. Every auto-run command is still judged in-line before it executes. Commands within policy run as they do today. A crossing command pauses or stops, and the decision is recorded.
How are background agents governed?
They act on your repositories from a cloud environment, so they are judged where they touch your systems, tied to the developer who launched them. The same policy applies.
Does it slow Cursor down?
No. The verdict returns in under 30ms on the device, in-line with the action.
Is this sold to individual developers?
No. Agen is deployed by the security or platform team across the fleet. Developers keep using Cursor as they do today.

Govern Cursor without taking it away.

Per-action verdicts on the device, a named developer behind every agent run.