How a telecom hardware vendor governs Claude Code and Codex across engineering, sales and marketing

At a glance
Communitech
Industry
Tech
Company size
Scaleup
Region
EU
Stack
Claude Code, OpenAI Codex CLI, MCP servers, ZTNA conditional access, EDAMAME Security, EDAMAME Hub
Agents governed
Claude Code for developers · Codex for sales and marketing
Governance scope
MCP servers and high-reach commands, company-wide
Enforcement
Posture-gated access through the existing ZTNA

Communitech, a telecom hardware vendor, standardized on Claude Code for its developers and Codex for sales and marketing. Its CISO used EDAMAME to govern how every agent uses tools — MCP servers and high-reach commands such as ssh, docker and shells — company-wide, and to bind access to that evidence through the company's ZTNA.

“Claude Code for engineering and Codex for sales and marketing arrived faster than any policy could follow. EDAMAME let us say yes to both: we see every agent, the MCP servers and commands it uses, and our ZTNA only grants access while a machine and its agents stay within policy.”

CISO

Telecom hardware vendor

Challenge

Communitech designs and sells telecom hardware. AI agents were already part of daily work, and new use cases kept arriving from every department. The company standardized on two: Claude Code for its developers, and OpenAI Codex for its sales and marketing teams — humans who now build with an agent without being security-trained developers.

The CISO's mandate was not to slow this down, but to support existing and emerging AI agent use cases with controls the whole company could live with.

Security challenges — governing what agents do, not only which apps they use

  • Agents act through tools: each agent reaches MCP servers and runs direct commands on the machine, with the access of the human who launched it. Knowing which AI apps were approved said nothing about which tools the agents actually used.

  • Two populations, one policy: developers and sales and marketing teams use different agents, but the CISO needed one governance model for both.

  • New use cases every month: rules written for today's agents had to stretch to the next ones without a new project each time.

  • Access had to follow the evidence: an agent going out of policy needed to change what its machine could reach, through the ZTNA the company already ran.

Bottom line: the company needed corporate-wide governance of agent tool use — MCP and direct commands — tied to access, without blocking the teams adopting AI.

Solution

Communitech deployed EDAMAME on the workstations of both populations and connected them to EDAMAME Hub. EDAMAME observes Claude Code and the local Codex sessions from outside the agent, at the operating system — no plugin inside either agent and no kernel driver.

One inventory of agents, MCP servers and commands

EDAMAME discovers every agent on each machine, the MCP servers and tools it reaches and how they authenticate, and the high-reach commands it runs, such as shells, ssh, scp and docker. The Hub's AI Governance page rolls this up across the company.

Company-wide governance with specific exceptions

With AI details shared from each device, the CISO set AI governance allowlists for the agents and MCP servers the company approves, scoped by group and with expiries; anything outside them is reported as not permitted. Exceptions are approved for one specific condition, never by switching off the check, and an agent that retries a command its own deny rules refused is itself a finding.

Access through the existing ZTNA

AI Agent Posture checks, intent divergence and attack-pattern findings feed each device's EDAMAME policy. EDAMAME Hub drives the company's ZTNA through its conditional-access integration: a machine that falls out of policy because of its agent loses access to the protected resources, and regains it automatically once the issue is fixed.

Results

AI adoption supported, not slowed

Developers keep Claude Code and sales and marketing keep Codex. New agents and MCP servers join the allowlists instead of waiting on a new security project.

One governance model for every department

The same evidence — agents, MCP servers, commands and findings — governs engineering and non-engineering teams alike, with every AI check carrying its OWASP GenAI, MITRE ATLAS and ISO/IEC 42001 references.

Access that follows agent behavior

Access to protected resources now depends on the live posture of each machine and the behavior of its agents, enforced by the ZTNA the company already runs.

Want to see EDAMAME on your environment?

We’ll help you validate posture-based access controls for repos, CI runners, and internal apps in days — not months.