One engineering team
Developers running Cursor, Claude Code, or CI agents with MCP tools, and the security owner who reviews what gets refused.
One team, the laptops and CI runners they work on, and the MCP servers they use. This page lists what is in scope, how setup works, what we measure together, and what the product won't do yet.
Developers running Cursor, Claude Code, or CI agents with MCP tools, and the security owner who reviews what gets refused.
One host runs PyxGrant: a Node service (22.13 or later) and one SQLite file. The collector and checkpoint run on the team's laptops and CI runners.
npm run collectnpm run collect -- proxyEvery number below comes from records the pilot produces on your hardware, not from our reporting.
How many of the team's agents and MCP servers were found and enrolled, and which were missed and why.
Every refusal reviewed. Each one that shouldn't have happened is counted and fixed with a rule change or an approval.
Median and slowest decision times on your own traffic, read from the timing each receipt records.
Your auditor verifies a sample of receipts with your key, without help from us.
Tell us which agents and MCP servers the team uses. We'll come back with a written scope against this build.