Windsurf logoWindsurfby Cognition
Govern · Windsurf

Cascade, governed on every action it takes.

Windsurf's Cascade agent edits files, runs terminal commands and calls MCP servers from the editor, and in turbo mode it does so without asking. Agen judges each action at runtime, against the developer behind it, and records the verdict. The team keeps Windsurf.

Enforced on the endpointAgenShieldStopped on the device, before execution. The gateway's verdict, enforced where the gateway cannot see.
<30ms
per-action verdict at runtime
1:1
a named developer behind every Cascade run
0
changes to the editor or its settings
1 day
from install to governing

How Agen governs Windsurf

  • AgenShield runs on the developer's machine and judges every file write, terminal command and MCP call Cascade makes, before it executes, in turbo mode or not.
  • Each action resolves to the developer's identity from your IdP. Cascade acts as a governed principal tied to a named person.
  • Policy returns a verdict in under 30ms: allow, mask, step up, hand to a human, or deny. Only the crossing action stops.
  • Every verdict is recorded with its full chain: developer, project, command, decision. Evidence exists at action time.
  • Windsurf's allow and deny lists, rules and team settings stay in place. Agen adds the central verdict and the record.
What Windsurf reaches

An agentic editor with the developer's reach.

Cascade is built to act. These are the things it can do on a machine with your developer's credentials.

Files across the workspace
Multi-file edits with full awareness of the project, and any path the developer can reach.
Terminal commands
Runs build, test, install and system commands. Turbo mode executes without confirmation outside the deny list.
MCP servers
Connects to internal tools and data sources exposed as MCP servers, with tokens held in local configuration.
Web fetch and previews
Reads URLs, runs local previews and can act on what it finds.
Memories and rules
Persists context across sessions, including anything sensitive that entered a conversation.
Enterprise deployment
Runs against self-hosted or hybrid model endpoints in enterprise plans, with the same local action reach.
Where the native controls stop

Turbo mode trusts the deny list. The deny list lives on the laptop.

Windsurf's allow and deny lists and team rules do useful work, and engineering should keep them. They are configured on the machine by the person the agent acts for.

01

The deny list is local

Which commands run without confirmation and which are refused are settings on each machine. Nothing central sees the configuration or the decisions it makes.

enforcement scopeone machine
02

Cascade acts as your developer

It runs on standing credentials that already reach your repos and CI. When a change lands badly, the author field is a person's name, and nothing on the machine says who chose the action.

author fielda person's name
03

Every MCP server is another door

Each server widens what a single prompt can reach. Which servers are permitted is decided in the same local configuration as everything else.

blast radiusgrows per server
04

No record anyone else can read

There is no central place to write one rule for every Cascade run, no per-action log outside the machine, and nothing to hand an auditor.

central audit trailnone
How Agen governs it

Same editor, same settings. One verdict per action.

The gateway decides. Shield enforces where the gateway cannot see. AgenShield sits on the device, does not change how Windsurf is used, and stops the crossing action before it executes.

01 · Discover
Find every Windsurf install
Endpoint telemetry surfaces every machine running Windsurf, every MCP server configured, and every developer using Cascade.
02 · Identify
Tie Cascade to a developer
Runs resolve to the developer's identity from your IdP. Cascade becomes a governed principal with a named owner.
03 · Govern
Judge each action in-line
File writes, terminal commands and MCP calls are evaluated per action against policy and identity, before they execute. Verdict in under 30ms.
04 · Evidence
Record the chain
Every action and verdict logged with developer, project, command and decision. Exported to your SIEM.
Shield

The gateway decides. Shield enforces where the gateway cannot see.

Cascade runs on the developer's machine, so AgenShield does the work: the gateway's verdict, enforced where the gateway cannot see. BrowserShield covers what the same developer pastes into AI tools in the browser.

AS
On the device
AgenShield
Primary for Windsurf

Out-of-policy actions like touching production secrets or mass-deleting files are stopped before they execute. Everything else flows. Ships through your MDM.

AgenShield · Cascade · dev-mbp-311blocked
Actionturbo · rm -rf ./customer-exports
Stoppedon device, before execution
Verdict28ms · logged
AgenShield in depth →
BS
In the browser
BrowserShield early access

Keys and sensitive data are recognised as they are pasted into AI tools, and the paste is blocked. Employees keep their tools. Only the leak stops.

BrowserShield · chatgpt.compaste blocked
Detectedcloud credentials in paste
Everything elseflows normally
Verdictlogged · same audit chain
Join the early-access program →
Same policy · same identity · same verdictShield overviewHow the gateway decides
Governed actions

What Cascade asks to do, and what policy says.

Illustrative verdicts for common Windsurf actions under a typical policy.

Typical per-action verdicts for Windsurf
Windsurf actionVerdictWhy
Multi-file edit inside the workspaceallowIn scope for the developer and the task. Logged, not interrupted.
Turbo mode runs the build and testsallowNormal engineering work on the developer's own machine.
Turbo mode runs a command that reads cloud credentialsdenyA credential has no place in an agent's context. Blocked before it executes, whatever the deny list says.
Delete files outside the workspacedenyOutside task scope on a device with the developer's privileges.
Push to a protected branchstep-upThe developer confirms from their phone. Approved, the push continues.
Query a customer database through an MCP servermaskThe query runs. Personal data is masked before it enters the model context.
Add an MCP server not on the approved listhuman-in-the-loopA new door. The agent's owner reviews it once, then policy remembers the answer.
Send workspace contents to an external URLdenyRecognised at the point of exfiltration and blocked in-line.

Verdicts are illustrative defaults. Every row is a policy you write once and Agen enforces per action, per identity.

Book a demo

See Windsurf governed, live.

Thirty minutes on the way your teams already use Windsurf. We show the verdict on each action, the named human behind the session, and the record it leaves. Bring your hardest question.

length30 minutes
formatlive, on your Windsurf setup
you seeevery action decided at runtime
Watch it happen

Cascade reaches for a secret. On a laptop.

It never crosses your network controls, and no log outside that machine would record the attempt. AgenShield stops it on the device.

on-device block · live product scene
From install to governing

Rolled out like software. The editor does not change.

Windsurf stays exactly as your engineers use it today.

Day 1
Ship AgenShield through your MDM
The endpoint agent deploys to developer machines with the tooling you already use. No editor extension to install.
Day 1
Connect your IdP
Cascade runs resolve to developers through Okta, Entra or any OIDC provider.
Week 1
Run observe-only
See every Cascade action across the fleet, including turbo-mode commands and MCP servers in use, before enforcing anything.
Week 2
Turn on the policies that matter
Start with credentials, deletes and protected branches. Developers only notice the crossing action.
The platform

Discover, Govern, Shield. One policy plane.

The same three capabilities govern Windsurf and every other agent you run, internal and external.

Expand a capability

Continuous discovery across your IdP, gateway, devices, cloud, and registries. Nothing has to self-register: agents are found, risk-scored, and resolved to a named human before they act.

  • Agentless and API-based across five surfaces
  • First-party, custom, and third-party agents alike
  • Every agent mapped to an owner, approver, and escalation
Agen Discover AI agent discovery flow: any identity provider, productivity suites and assistants, cloud, gateway, endpoints, and MCP server registries all feed one agent registry where every AI agent is inventoried, risk-scored on arrival, given a named human owner, and shadow AI is surfaced.
Discovery pulls from five surfaces into a single agent registry — no SDK self-registration required.
ClosesWhich agents are running that nobody registered?
no SDK required5 surfacesowner-mapped
Discover in depth →

FAQ

Questions, answered.

Does Agen replace Windsurf's allow and deny lists?
No. Engineering keeps them. Agen adds a central verdict on each action, anchored to the developer's identity, and a record outside the machine. The two layers do different jobs.
What happens in turbo mode?
Nothing changes for the developer. Every command is still judged in-line before it executes. Commands within policy run as they do today. A crossing command pauses or stops, and the decision is recorded.
Does it slow Cascade down?
No. The verdict returns in under 30ms on the device, in-line with the action.
Does this work with self-hosted or hybrid Windsurf deployments?
Yes. AgenShield governs the action on the device regardless of where the model runs.
Is this sold to individual developers?
No. Agen is deployed by the security or platform team across the fleet. Developers keep using Windsurf as they do today.

Govern Windsurf without taking it away.

Per-action verdicts on the device, a named developer behind every Cascade run.