macOS
Managed endpoint coverage with OS-specific observation sources, controls, deployment requirements, and known differences.
Coding agents operate inside the developer trust boundary. Pavri adds agent-specific context to discover assistants, govern configured MCP and endpoint actions, and reconstruct sessions.
Pavri coding-agent coverage focuses on managed developer endpoints across macOS, Windows, Linux, with assistant discovery, MCP visibility, workspace context, policy, local evidence, and investigation. Observation and enforcement depth varies by OS, assistant, permissions, action type, and control point.
Pavri connects assistant identity to user, endpoint, workspace, repository, process, file, network, browser, credential, Git, MCP, policy, and session evidence where those sources are available.
Managed endpoint coverage with OS-specific observation sources, controls, deployment requirements, and known differences.
Managed endpoint coverage with OS-specific observation sources, controls, deployment requirements, and known differences.
Managed endpoint coverage with OS-specific observation sources, controls, deployment requirements, and known differences.
Configured MCP tool calls can be held for approval through the Local MCP Broker. PolicyCache supports local policy evaluation. Local evidence and write-ahead logs preserve events for upload and investigation.
Cursor asks prod-deploy to run mcp.deploy. Policy PROD-DEPLOY-04 holds the configured MCP tool call for approval through the Local MCP Broker.
| Observation source | Assistant, process, workspace, file, Git, network, browser, MCP, and local evidence sources where permissions allow. |
|---|---|
| Inline controls | Local MCP Broker controls configured MCP calls; endpoint controls vary by action and entitlement. |
| Deployment requirements | Managed endpoint enrollment, endpoint sensor, PolicyCache, and approved privacy configuration. |
| Observation source | Assistant, workspace, process, ETW-backed evidence, file, network, Git, MCP, and local event context where available. |
|---|---|
| Inline controls | Configured MCP calls can route through the Local MCP Broker. ETW is evidence and is not depicted as generic denial. |
| Deployment requirements | Managed endpoint enrollment, OS-specific sensor permissions, PolicyCache, and evidence upload configuration. |
| Observation source | Assistant, shell, process, workspace, file, Git, network, MCP, and local evidence sources where deployed. |
|---|---|
| Inline controls | Configured MCP calls can route through the Local MCP Broker; other enforcement varies by action path. |
| Deployment requirements | Managed endpoint enrollment, supported distribution profile, PolicyCache, and local evidence/WAL. |
Coverage depth varies by OS, assistant, permissions, action type, and control point.
Start with MCP, workspace, repository, terminal, credential, and production-action context.