Skip to main content
Agent Governance gives Enterprise security teams visibility into agent activity and installed software, along with control over what agents can do. It covers tools, MCP calls, shell commands, skills, and plugins that would otherwise run mostly outside the security team’s view.

Features

Observability and control

Telemetry and inventory give security teams a shared view of agent activity and installed software. MCP and shell policies run on the developer’s device, inside Corridor’s agent hooks, before an action executes. These controls are designed to stop a cooperating agent from taking an action your team has ruled out. When a control cannot evaluate an action, it fails open so it does not block development.

Supported agents

Corridor delivers Agent Governance through hooks installed by the Corridor CLI or IDE extension: ✓ means the capability is supported when Agent Governance is enabled for the team. The Artifact Inventory row covers coding-agent configuration. Editor-extension inventory also covers the VS Code family and JetBrains IDEs, regardless of which coding agent is in use. GitHub Copilot has no hook interface, so these capabilities do not cover it.
Agent Governance is rolling out to Enterprise teams. If you don’t see these pages in your dashboard yet, contact support@corridor.dev or your Corridor representative.

Availability and enablement

  • Agent Governance is available on the Enterprise plan, including Enterprise trials.
  • In Team Settings → Agent Observability, the Agent Telemetry and Artifact Inventory toggles control what Corridor collects from your developers’ machines. Turning a stream off makes the server drop incoming data and connected clients stop sending it. Only team Owners can change these settings.
  • Governance dashboards, including Agent Sessions, are visible to team Owners and Admins.
  • Only team Owners can change MCP and shell rules.

Where to find it

Open Governance in the Corridor dashboard:
  • Analytics: Tool Call Analytics
  • Timeline: the event stream, session list, and shell usage views
  • Agent Sessions: the per-conversation session browser
  • Inventory: the artifact catalog, with an All view and separate MCP, Skills, Hooks, Plugins, and Extensions views
  • MCP: MCP server and tool policy
  • Shell Controls: shell command rules

Next steps

Agent Telemetry & Timeline

See what your agents are doing

Artifact Inventory

See what’s installed across your team

MCP Tool Controls

Set allow/block policy by server and tool