Solution Brief
Govern what Claude Code
and Cowork agents can access and do
Set policy for the apps, data, tools, and MCP servers Claude Code and Cowork can use, and the actions they can take.
Claude Code and Cowork agents act through MCP connections and direct integrations, bypassing every layer of your security architecture.
Obsidian sits where the activity actually happens, so risky actions are detected and stopped before they run.
- Know what every agent can reach: See the owner, models, skills, permissions, apps, files, tools, and MCP servers behind each Claude agent
- Remove access the agent doesn't need: Find excessive permissions and prevent sensitive files and credentials from entering agent context
- Stop actions that violate policy: Block unapproved tool calls and prohibit destructive actions before they run