per-agent kill switch, enforcement mode & IAM profile — live agents pick changes up within 30 s
Manage every agent from one place
Claude Code, Codex, Cursor, and other agents auto-register the first time they run in a
Prismor-enabled workspace. Blocked denies every tool call from that agent
(kill switch) · Observe logs threats without blocking ·
Enforce blocks them in real time. Saved to .prismor/agents.yaml.
Agent
Status
Mode
IAM Profile
Calls
Blocked
Last Seen
Enabled
Loading agents…
Need this across your whole org?
Prismor Enterprise adds an org-level kill switch — pause a compromised agent on every
enrolled machine at once, with signed policy a local re-enable can't override.
Talk to us →
Live Sessions
pause Prismor, clear scope, or unblock a stuck agent — per-agent kill switch lives in the Agents tab
Loading sessions…
All Sessions
full session log — click session row above for controls
Session↕
Agent↕
Workspace↕
Risk Score↕
Findings↕
Last Active↕
Policy Control
human-only — changes take effect within 30 s on running agents
Detection rules
Toggle individual rules for this project. Disabling a rule stops it
blocking and flagging. Saved to .prismor/policy.yaml;
live agents pick it up within 30 s.
—
Loading…
Global policy
Applies to every project on this machine unless overridden at the project level.
Path: ~/.prismor/policy.yaml
Loading…
Enforcement mode
observe = log only · enforce = block
Project policy
Overrides global settings for this project only. Stored in
.prismor/policy.yaml alongside your code.
Merge precedence: enterprise > project > global.
Loading…
Enforcement mode
observe = log only · enforce = block
Not enrolled
Enroll this device in a Prismor org to receive centrally-managed policies.
Run: prismor enroll <token>
Read-only — managed by your org admin in the Prismor web dashboard.
Effective policy
What actually runs on this machine right now — global + project + enterprise merged together.
Enterprise settings take precedence; core protections can never be disabled.
Read-only — edit Global or Project to change this.
Fleet
org-wide visibility across every enrolled device
Fleet view is a Prismor Enterprise feature
This local dashboard shows agents and sessions on this machine. Fleet view gives
your security team the same picture across every developer laptop and CI runner in the org —
live sessions, findings, per-device policy status, and a remote kill switch — streamed as
redacted telemetry to a dashboard you host.
Device
User
Agents
Mode
Findings (7d)
Last Seen
mbp-eng-042
priya@acme.dev
claude-code, codex
enforce
3
2m ago
mbp-eng-017
sam@acme.dev
claude-code
enforce
0
11m ago
ci-runner-08
—
codex
enforce
1
just now
mbp-eng-063
jo@acme.dev
cursor
observe
7
1h ago
mbp-eng-029
lee@acme.dev
claude-code, cursor
enforce
0
3h ago
Illustrative preview — live fleet data is part of Prismor Enterprise
Rolling Prismor out to a team?This local dashboard stays free and open source. Enterprise adds fleet visibility, signed remote policy, org kill switch, and audit history.
The local dashboard is free and open source, forever — Enterprise adds the cloud control plane on top, nothing here is taken away.
Prefer chat? Join our Discord.