How a telecom hardware vendor governs Claude Code and Codex across engineering, sales and marketing
Communitech, a telecom hardware vendor, standardized on Claude Code for its developers and Codex for sales and marketing. Its CISO used EDAMAME to govern how every agent uses tools — MCP servers and high-reach commands such as ssh, docker and shells — company-wide, and to bind access to that evidence through the company's ZTNA.
“Claude Code for engineering and Codex for sales and marketing arrived faster than any policy could follow. EDAMAME let us say yes to both: we see every agent, the MCP servers and commands it uses, and our ZTNA only grants access while a machine and its agents stay within policy.”
CISO
Telecom hardware vendor

Challenge
Communitech designs and sells telecom hardware. AI agents were already part of daily work, and new use cases kept arriving from every department. The company standardized on two: Claude Code for its developers, and OpenAI Codex for its sales and marketing teams — humans who now build with an agent without being security-trained developers.
The CISO's mandate was not to slow this down, but to support existing and emerging AI agent use cases with controls the whole company could live with.
Security challenges — governing what agents do, not only which apps they use
Agents act through tools: each agent reaches MCP servers and runs direct commands on the machine, with the access of the human who launched it. Knowing which AI apps were approved said nothing about which tools the agents actually used.
Two populations, one policy: developers and sales and marketing teams use different agents, but the CISO needed one governance model for both.
New use cases every month: rules written for today's agents had to stretch to the next ones without a new project each time.
Access had to follow the evidence: an agent going out of policy needed to change what its machine could reach, through the ZTNA the company already ran.
Bottom line: the company needed corporate-wide governance of agent tool use — MCP and direct commands — tied to access, without blocking the teams adopting AI.
Solution
Communitech deployed EDAMAME on the workstations of both populations and connected them to EDAMAME Hub. EDAMAME observes Claude Code and the local Codex sessions from outside the agent, at the operating system — no plugin inside either agent and no kernel driver.
One inventory of agents, MCP servers and commands
EDAMAME discovers every agent on each machine, the MCP servers and tools it reaches and how they authenticate, and the high-reach commands it runs, such as shells, ssh, scp and docker. The Hub's AI Governance page rolls this up across the company.
Company-wide governance with specific exceptions
With AI details shared from each device, the CISO set AI governance allowlists for the agents and MCP servers the company approves, scoped by group and with expiries; anything outside them is reported as not permitted. Exceptions are approved for one specific condition, never by switching off the check, and an agent that retries a command its own deny rules refused is itself a finding.
Access through the existing ZTNA
AI Agent Posture checks, intent divergence and attack-pattern findings feed each device's EDAMAME policy. EDAMAME Hub drives the company's ZTNA through its conditional-access integration: a machine that falls out of policy because of its agent loses access to the protected resources, and regains it automatically once the issue is fixed.
Results
AI adoption supported, not slowed
Developers keep Claude Code and sales and marketing keep Codex. New agents and MCP servers join the allowlists instead of waiting on a new security project.
One governance model for every department
The same evidence — agents, MCP servers, commands and findings — governs engineering and non-engineering teams alike, with every AI check carrying its OWASP GenAI, MITRE ATLAS and ISO/IEC 42001 references.
Access that follows agent behavior
Access to protected resources now depends on the live posture of each machine and the behavior of its agents, enforced by the ZTNA the company already runs.
Want to see EDAMAME on your environment?
We’ll help you validate posture-based access controls for repos, CI runners, and internal apps in days — not months.