CONTROL PLANE FOR INFRASTRUCTURE AGENTS

Your coding agent has access.
Give it boundaries.

Keep Codex and Claude Code fast. Give every infrastructure session an exact scope, shared rules, approval points, remote stop, and proof your team can inspect.

Local enforcement. No long-lived cloud credentials sent to Misconfig.
misconfig run codexLIVE
Update the production CPU alarms to 80%.
1READgrafana.alerts.listALLOWED
2CHANGEgrafana.alerts.updateAPPROVAL
3VERIFYthreshold = 80WAITING
POLICYproduction-guardrails@7signed · cached locally
SCOPEproduction / grafana2 actions in boundary
CODEX + CLAUDE CODELOCAL POLICY DECISIONSREMOTE SESSION STOPRETAINED ACTION PROOF

LOCAL PERMISSIONS ARE NOT TEAM POLICY

“Full access” is a machine setting.
Production needs a control plane.

Agent permission modes decide what a model may attempt on one laptop. They do not define which account, cluster, environment, or operation your company accepts. Misconfig adds that shared boundary without replacing the agent.

YOUR AGENT

Can I run this command?

  • Workspace and shell access
  • Local approval mode
  • Internet access
  • Agent-native tools
+
MISCONFIG

May this session change that system?

  • Named infrastructure scope
  • Versioned team rules
  • Exact approval points
  • Remote stop and proof

ONE SESSION. FOUR CONTROLS.

Fast for the engineer.
Explainable to everyone else.

SCOPE

Where this session may act

Account, cluster, environment, resource, operation, and credential mode are explicit.

RULES

What it may complete

Shared, versioned rules decide locally. A prompt cannot widen them.

APPROVAL

Where a human steps in

Hold exact actions for review without turning every harmless read into a meeting.

STOP

End authority remotely

Stop a named session from the console. Cached policy expires and the runtime fails closed.

THE ENGINEER WORKFLOW

One command in.
One accountable session out.

  1. 01

    Start inside your workspace

    Launch Codex or Claude Code through Misconfig. Your original agent configuration stays yours.

  2. 02

    Bind the infrastructure scope

    Choose the AWS account, Kubernetes context, credential mode, tools, and policy release for this session.

  3. 03

    Let the agent work

    Reads move. Mutations are allowed, denied, or held for approval by deterministic policy on your machine.

  4. 04

    Keep the proof

    The console groups each decision and completion into one action trace with exact session and policy identity.

THE SESSION, NOT THE THEATRE

See what the agent actually did.

One view for the operator, one retained record for the team. Decisions and completions are grouped into logical actions. Unknown usage stays unknown. Observed execution is never presented as provider verification.

  • Tool calls and failed calls
  • Allowed, denied, and approval-held actions
  • Exact profile, policy, adapter, and credential mode
  • Remote stop reason and receipt history
Open founder staging
SessionsLIVE DATA
production alarmsCodex · running
cluster inventoryClaude Code · stopped
database reviewCodex · completed
MODELCodex / Claude CodePOLICYproduction-guardrails@7CREDENTIALAWS attach modeSESSIONrunning / 18m 42s
grafana.alerts.listpolicy allow · observed12:41:08
grafana.alerts.updatehuman approval required12:41:11
kubectl delete podoutside declared scope12:42:02

CREDENTIALS STAY AT THE EDGE

The decision happens before the tool.

The local Go runtime launches the agent with a temporary native configuration. It evaluates signed policy before each supported tool call, then spools a redacted receipt for the control plane. If policy is missing, stale, stopped, or invalid, governed actions fail closed.

ENGINEERCodex or Claude CodeLOCALMisconfig runtimeEXISTING ACCESSCloud and cluster tools
signed policy + stopredacted receipts

FOUNDER STAGING

Start with one real session.

Codex direct tool decisions are live-proven. Claude Code hooks, public package signing, brokered cloud credentials, and broader provider verification remain release gates. We show those boundaries instead of hiding them.

Session control plane LIVECodex direct hooks LIVEClaude live matrix PREVIEWBrokered credentials PLANNED

KEEP THE AGENT. CONTROL THE SESSION.

Move fast without making
“full access” the policy.

Open founder staging or talk to us about governing your first Codex or Claude Code infrastructure workflow.