Do we need to change our agents?
No. Endeem works with coding agents like Claude Code and Codex, and assistants like Claude Cowork and Microsoft Copilot, with no changes to the agent or to how your teams work.
How is this different from hooks?
A hook sees the command the agent chose to run, like python cleanup.py. Endeem sees each request that command sends, so a script the agent writes and runs a second later is still checked, request by request. Hooks also only work in agents that support them and assume the agent harness is trusted. Endeem doesn’t need the agent’s cooperation.
How is this different from an AI or MCP gateway?
A gateway only sees traffic routed through it. An agent that changes its endpoint, uses a personal key or calls an API directly goes around it. Endeem runs on the same machine as the agent, so those requests still go through Endeem.
Why isn’t our identity provider enough?
Endeem identifies the agent from its running process on the machine, including who signed it and who started it. It doesn’t rely on what the agent says about itself or on a directory entry.
What happens if Endeem’s cloud is unavailable?
Your rules run on the device and keep enforcing. Anything your rules don’t decide is blocked until the intent check can answer again.
Does blocking an agent block the employee?
No. A block only applies to the agent’s requests. The employee keeps their own access and can keep working.