👋 Hey everyone,
We’ve been seeing Claude Code spread well beyond engineering. Marketing teams exploring codebases, product managers reading configs, data analysts grepping logs.
But there is a gap. There is no central, enforceable way to control what those agents can actually do. Hooks exist, but they are local config, per developer, opt-in. That means no consistent enforcement across the org and no reliable way to see what agents actually did.
🎉
Today, we are introducing centralized authorization for Claude Code agents.
Every tool call is intercepted and checked against policy before it runs. That gives you control over what agents are allowed to do, at the moment they act:
• Allow or deny decisions on every tool call, not just monitoring
• Role-based controls so engineers can use Bash while other teams stay read-only
• Full audit log tied to the user behind each agent action
• Policies as code, versioned, reviewed, and updated without redeploying anything
Policies and audit logs are managed in Cerbos Hub, so you have one place to control access and understand what agents are doing across your org. If you want to see how it works or try it out, we’re around and happy to help:
👉
https://www.cerbos.dev/ecosystem/claude-code
👉
https://www.cerbos.dev/workshop