AI Governance
AI governance for every agent: discover, audit, approve
Cursor, Claude Desktop, Claude Code, Codex, OpenClaw, and Hermes are already on your machines, and every week they reach a new MCP server or tool. EDAMAME discovers every agent from outside the agent, audits each check in the frameworks your auditors use, and lets you approve each new agent, MCP server or tool as a specific, time-limited exception, without switching off the check for everything else. Zero install into the agent. Every observation rolls up to EDAMAME Hub. Security that accelerates humans.


Discover
Discover: day-one answers. Zero config. Nothing to install into the agent.
Most teams still cannot answer the basics: which AI agents are running, which MCP servers and tools each can reach, whether a harness confines it, and how efficiently humans use them. EDAMAME answers that on day one — the Exposure view, a Self-Augmentation Score, and a Path of Enlightenment — automatically from outside the agent. When you need a verdict on behavior, Agentic Security adds divergence scoring and attack-pattern detection.
Exposure
See every AI agent on the machine — approved or not — which MCP servers and tools it reaches, how they authenticate, whether a governance harness confines it, and its blast radius if compromised. One fleet-health read tells you if AI work is safe right now.
AI work safety
In thirty seconds: are agents healthy, wasting tokens, stuck in failures, or drifting? A ranked list and alert feed so humans know what to fix first.
Path of Enlightenment
A guided journey from Awakening to Enlightened — driven by how well you augment yourself with AI, with one clear next step when security or blast-radius gates hold you back.
Self-Augmentation Score
A score humans can raise: how effectively they use skills and tools, where context tax piles up, and which skills are used, dormant, or dead.
Audit and govern
From one host to fleet policy: audit every check, approve specific exceptions.
What EDAMAME sees on each host becomes ordinary posture checks in EDAMAME Hub — agents without a governance harness, unconfined agents with a dangerous blast radius, paused observers, unprotected MCP servers. Every AI check carries its framework references — OWASP GenAI, MITRE ATLAS, Agentic Trust Controls, ISO/IEC 42001 and ISO 27001 — so an auditor reads pass or fail in the vocabulary of the standard being assessed. The Hub’s AI Governance page then reads the whole fleet: agent adoption, harness coverage, every MCP server declared anywhere with its authentication state, the conditions that recur most across devices, and what no allowlist permits. Exceptions are approved for a specific agent, MCP server or condition, never by switching off the check — approve one condition on one agent and everything else that check covers keeps being flagged — and allowlists can restrict which agents and MCP servers may exist, per domain, group or device, with an expiry (Enterprise plan).
Every host. Same structural truth.
EDAMAME Security runs the structural pass on the developer workstation; EDAMAME Posture runs the same pass headless on CI/CD runners and any server running AI agents, cloud or self-hosted, such as OpenClaw and Hermes hosts.
• Agent inventory with observed-coverage validation
• MCP server and tool inventory per agent
• Blast radius, trust zones, and sandbox harness coverage
Approve specific exceptions, enforce through Zero Trust
Each observation lands where CISOs already work: device score, Security Checks with their framework chips, failed checks, Security Score events, Engagement escalations, and the AI Governance page. Turn any of these into posture-gated conditional access — only compliant hosts stay on your IdP and provider allow-lists, and Netskope, your IdP, or your network denies a flagged host the critical resources behind it.
• Agents present but no governance harness
• Unconfined agents with a host amplifier
• Discovered agents with a paused observer
Every endpoint, every framework
One governance story across workstations, runners, and agent hosts
Not just the developer laptop. The same discovery, audit, and governance cover workstations, CI/CD runners, isolated VMs, and any server running AI agents, cloud or self-hosted — so exposure, blast radius, framework coverage, and human-augmentation questions get the same evidence-backed answer on every machine that touches your code.
Developer workstations
See Cursor, Claude Desktop, Claude Code, Codex, and more on the laptop — every agent, its MCP servers and tools, and its blast radius, with nothing installed into the agent.
Runners and agent hosts
The same structural pass, headless, on CI/CD runners, isolated VMs, and any server running AI agents, cloud or self-hosted — OpenClaw and Hermes hosts included.
Frameworks on every AI check
A graded OWASP GenAI scorecard from the same structural facts — and every AI check carries its MITRE ATLAS, Agentic Trust Controls, ISO/IEC 42001 and ISO 27001 references. Coverage, not certification.
From governance to security
Governance first. Verdict when you need it.
Discovery, audit, and allowlists tell you who is running, what it can reach, and what is permitted to exist. Agentic Security judges behavior — intent divergence and attack-pattern findings — and the response goes through the Zero Trust layer you already run, via EDAMAME Hub. Those findings map to OWASP GenAI and the runtime-observable MITRE ATLAS subset on the EDAMAME agents page; ATLAS is detection evidence, not structural inventory.
Intent divergence
Compare what the agent says it is doing with what the machine actually does — processes, files, network, posture — and score the gap on an evidence trail.
Attack-pattern findings
Catch credential harvest, token exfiltration, and sensitive-file access — the patterns behind the axios npm RAT, tj-actions, and litellm attacks.
Response through Zero Trust
When a critical finding lands, EDAMAME Hub drops the device tag and your Zero Trust layer — Netskope, your IdP, your network — denies that host the critical resources, automatically.

