By Jens Ernstberger.
Published 2026-03-14.
Updated 2026-10-05.
Every AI agent that does something useful needs access to real systems. It can read a repository, send a message, change a workflow, or call an API on behalf of a user. Giving it access is easy. Knowing what it does with that access, and keeping those actions within bounds, is harder.
An agent can use an approved tool with valid permissions and still take the wrong action. A coding agent asked to fix a test might also change the release workflow. A support agent asked to read one customer record might export thousands. Security teams need to see what agents attempt and apply policy before those actions happen.
That's why we built Kontext: runtime security for your AI workforce. See which agents are running, understand what they can access, and control what they do.
---
Three principles
Control before execution. Policy belongs where an agent is about to act. Kontext evaluates tool requests locally and can block prohibited actions at supported hooks before the tool runs.
Observable by default. Teams should be able to review what an agent attempted, which policy applied, and what happened next. Kontext connects supported tool activity with decision evidence so you can investigate incidents and validate controls.
Fits your stack. Install Kontext once and keep using your agents normally. Start in observe mode to see what policy would deny, then enable enforcement when you've validated the restriction against real activity.
---
What you get
- Agent Discovery & Access Posture: discover agents in connected environments and understand the tools, systems, and data they can access.
- Runtime Policy Enforcement: define permitted actions and block prohibited activity before execution at supported control points.
- Activity Monitoring & Risk Detection: understand agent activity, identify risky actions, and retain decision evidence for investigation.
- Spend Management & Optimization: understand agent spend, identify waste, and find savings by reducing unnecessary costs.
Together, these give teams a practical way to understand and control their AI workforce. Begin with visibility, validate one meaningful restriction, and expand from there.
---
Who this is for
You're a security team trying to understand which agents are running and what they can reach. You're a platform team rolling out coding agents across the organization. You're a developer who wants to keep using familiar tools with clear boundaries around sensitive actions.
Kontext gives you a path from observed activity to policy you can test and enforce.
---
Get started
The public repository documents the installation path. On your Mac, install Kontext:
brew install kontext-security/tap/kontextCreate an install token in the Kontext dashboard, then connect your Mac and verify the installation:
kontext setup
kontext doctorContinue using Claude Code or Codex normally. Setup installs their hooks and starts the local daemon; Codex hooks must also be trusted in Codex. Cowork uses the same runtime through hooks configured inside its environment. The agent support matrix explains the exact installation and enforcement coverage.
Start in observe mode, review which actions policy would stop, and enable enforcement when you're ready. Read the docs or explore Kontext for security teams.