Govern What Claude Agents Can Access and Do

Set guardrails for Claude Code and Claude Cowork permissions and actions across the apps, data, and systems they use.

Always be in control of what Claude Code and Cowork agents are doing

Claude Code is allowed to read SSH keys and overwrite code in GitHub, while Cowork queries tables in Snowflake and sends the data over Slack. And none of it is governed today. Obsidian Security alerts you when agents hold risky access or take dangerous actions, and enforces policy on every agent and action.

Remove risky privilege and access

Find and fix every agent holding more access than allowed.
Cut over-privilege: Alerts show if destructive actions have occurred so you can right-size permissions
Shrink the blast radius: Know which agents have excessive access so their reach remains tightly scoped
Prioritized remediation: Risk factors scored by criticality show what remediation to tackle first

Manage sensitive data access

Ensure only approved agents can reach sensitive business data.
Live access mapping: Know exactly what data agents can touch, so nothing is accidentally leaked, published, moved, or modified
Protect sensitive files: Detect when Claude agents can read sensitive local files into their context, like cloud credentials or private keys
Detect secrets in skills: Surface Claude agents using skills with embedded credentials or other sensitive information

Control MCP and tool usage

Keep every Claude Code and Cowork agent inside the tools and MCP servers you've approved.
Inventory your AI infrastructure: Always know the models, skills, hooks, plugins, and MCPs Claude agents use
Eliminate shadow IT: See when agents connect to personal or unsanctioned third-party systems
Block unapproved systems: Enforce guardrails so agents can never complete tool calls to unsanctioned MCPs or applications

Prevent destructive actions

Build and enforce flexible guardrails at runtime so every agent action is safe, approved, and policy-aligned.
Block, warn, or require approval: Enforcement fits your risk tolerance, with options to log, prevent, or prompt human sign-off
Exceptions ensure flexible enforcement: Choose which users, agents, and actions each policy applies to
Audit policy actions: See every time an agent triggers a policy, with evidence of the action taken

Obsidian fills the gaps legacy security tooling leaves

Claude Code and Cowork agents act through MCP connections and direct integrations, bypassing every layer of your security architecture. Obsidian sits where the actions actually happen, so risky activity is detected and stopped before it runs.

Explore the architecture gap
Agent actions bypass network gateways
Claude acts through OAuth, APIs, and MCP servers, traffic no gateway ever sees. Only Obsidian correlates activity across the agent and your connected apps, so nothing slips through.
Identity providers can’t spot over-privilege
Obsidian maps the true entitlements behind each agent and scores over-privilege using risk factors drawn from years of breach intelligence.
Native Anthropic controls miss risk
Anthropic's built-in controls stop at inventory and configuration. Obsidian surfaces the risk factors and alerts that tell you when an agent is dangerous.