The deny list is local
Which commands run without confirmation and which are refused are settings on each machine. Nothing central sees the configuration or the decisions it makes.
Windsurf's Cascade agent edits files, runs terminal commands and calls MCP servers from the editor, and in turbo mode it does so without asking. Agen judges each action at runtime, against the developer behind it, and records the verdict. The team keeps Windsurf.

Cascade is built to act. These are the things it can do on a machine with your developer's credentials.
Windsurf's allow and deny lists and team rules do useful work, and engineering should keep them. They are configured on the machine by the person the agent acts for.
Which commands run without confirmation and which are refused are settings on each machine. Nothing central sees the configuration or the decisions it makes.
It runs on standing credentials that already reach your repos and CI. When a change lands badly, the author field is a person's name, and nothing on the machine says who chose the action.
Each server widens what a single prompt can reach. Which servers are permitted is decided in the same local configuration as everything else.
There is no central place to write one rule for every Cascade run, no per-action log outside the machine, and nothing to hand an auditor.
The gateway decides. Shield enforces where the gateway cannot see. AgenShield sits on the device, does not change how Windsurf is used, and stops the crossing action before it executes.
Cascade runs on the developer's machine, so AgenShield does the work: the gateway's verdict, enforced where the gateway cannot see. BrowserShield covers what the same developer pastes into AI tools in the browser.
Out-of-policy actions like touching production secrets or mass-deleting files are stopped before they execute. Everything else flows. Ships through your MDM.
Keys and sensitive data are recognised as they are pasted into AI tools, and the paste is blocked. Employees keep their tools. Only the leak stops.
Illustrative verdicts for common Windsurf actions under a typical policy.
| Windsurf action | Verdict | Why |
|---|---|---|
| Multi-file edit inside the workspace | allow | In scope for the developer and the task. Logged, not interrupted. |
| Turbo mode runs the build and tests | allow | Normal engineering work on the developer's own machine. |
| Turbo mode runs a command that reads cloud credentials | deny | A credential has no place in an agent's context. Blocked before it executes, whatever the deny list says. |
| Delete files outside the workspace | deny | Outside task scope on a device with the developer's privileges. |
| Push to a protected branch | step-up | The developer confirms from their phone. Approved, the push continues. |
| Query a customer database through an MCP server | mask | The query runs. Personal data is masked before it enters the model context. |
| Add an MCP server not on the approved list | human-in-the-loop | A new door. The agent's owner reviews it once, then policy remembers the answer. |
| Send workspace contents to an external URL | deny | Recognised at the point of exfiltration and blocked in-line. |
Verdicts are illustrative defaults. Every row is a policy you write once and Agen enforces per action, per identity.
Thirty minutes on the way your teams already use Windsurf. We show the verdict on each action, the named human behind the session, and the record it leaves. Bring your hardest question.
It never crosses your network controls, and no log outside that machine would record the attempt. AgenShield stops it on the device.
Windsurf stays exactly as your engineers use it today.
The same three capabilities govern Windsurf and every other agent you run, internal and external.
Continuous discovery across your IdP, gateway, devices, cloud, and registries. Nothing has to self-register: agents are found, risk-scored, and resolved to a named human before they act.
Per-action verdicts on the device, a named developer behind every Cascade run.