Endpoint security

Add agent-specific context to developer endpoints.

Pavri complements EDR by connecting coding assistants to users, endpoints, workspaces, repositories, MCP tools, local policy, and evidence without claiming to replace endpoint security.

Pavri is complementary to EDR. It adds AI coding assistant, workspace, MCP, policy, and session context while endpoint observation and enforcement vary by operating system, assistant, permissions, action type, and control point.

Complement to EDR

Endpoint tools see events. Pavri adds agent context.

Coding agents often act through normal developer tools. Pavri connects endpoint observations with assistant identity, workspace, repository, MCP server, tool, policy, and decision context.

Assistant and workspace identity

Tie activity to the assistant, user, endpoint, repository, and workspace context.

MCP and local policy

Route configured MCP tool calls through the Local MCP Broker and evaluate policy from the PolicyCache.

Evidence and privacy

Preserve local evidence with clear source labels and deployment controls.

Endpoint boundary

Windows ETW is evidence, not a generic denial mechanism.

Pavri does not depict endpoint observation as universal inline enforcement. Inline controls, evidence sources, and response actions depend on OS, assistant, permissions, and the specific action path.

Persona proof

Assistant attribution, workspace context, and MCP control.

Alerted
Actor
Claude Code
Action
read_sensitive_path
Target
developer credential path
Policy
SECRETS-PATH-09
Reason
Assistant, workspace, process, file path, repository, and user context are preserved for investigation.
Control point
endpoint sensor and local evidence
  1. Assistant attribution ties activity to user, endpoint, workspace, process, and repository.
  2. MCP inventory shows connected servers, tools, and broker routing mode.
  3. EDR keeps endpoint telemetry; Pavri adds agent-specific action context.
Next step

Review coding-agent endpoint architecture.

Map OS-specific sources, Local MCP Broker behavior, PolicyCache, and local evidence/WAL into your endpoint program.