Claude Code, Claude Desktop, Cowork, and Claude in Chrome put a full agent runtime on every employee laptop — with file, shell, and browser access. Ospiri watches what they do and controls what they touch.
Book a demoAnthropic ships four distinct agent runtimes that read, write, and execute on the device — sanctioned or not.
Terminal agent that reads/writes files, runs shell commands, and spawns sub-agents. Configured in ~/.claude/ and ~/.claude.json; a bypassPermissions mode disables prompts entirely.
The same agentic engine, no terminal required. Runs inside a local VM with read/write access to user folders, parallel sub-agents, and scheduled recurring tasks.
Extension that navigates, clicks, fills forms, and reads page and network content on the user's behalf.
Screen, mouse, and keyboard control across applications — actions that land outside any Claude-managed sandbox.
SKILL.md files in ~/.claude/skills/ auto-load next session. No signing, no sandbox, no review; distributed through open registries.~/.claude.json and .mcp.json. One rewrite redirects authenticated traffic.hooks/hooks.json execute on session start and around every tool call.CLAUDE.md injects instructions into every session in a project.~/.claude.json post-install.managed-settings.json gives static allow/deny lists, and enterprise audit surfaces cover chat — but desktop agent activity runs in a VM your EDR can't see into, MCP payloads are never inspected, and skills load with no scan. Personal accounts see none of it.Ospiri connects to Anthropic's enterprise admin surfaces and correlates what the console reports with what actually happened on the device.
.env, /secrets, and production paths. Risky writes land in a copy-on-write sandbox — the agent keeps working, your data never moves./finance, spawns unusual sub-agents, or calls new domains at 3am — correlated across endpoint, browser, and identity.SKILL.md, hook, and CLAUDE.md is scanned pre-flight and re-scanned on update — poisoned instructions, embedded secrets, and unapproved workflows blocked before a line executes.~/.claude.json and .mcp.json, monitor tool-call traffic in flight, and enforce per-agent allow-lists — rogue and look-alike servers surfaced, every call logged and replayable.Book a demo. We'll scope a deployment for your environment.
Book a demo