Agent proposes an action
submitClaude Code, an MCP client, or a production agent describes the intended action.
Cordum puts policy, approval, and redacted audit evidence in front of Claude Code, MCP tools, shell commands, workflows, and production changes.
Source-available core · Local Edge path available today · Managed fleet enforcement requires endpoint controls
Held before execution
An authorized reviewer can approve or reject this exact action hash.
Works alongside the frameworks and clouds you already run
Logos indicate ecosystem compatibility, not shipped plugins.
Hover or focus this section to pause the scrolling integration list.
Edge is the concrete first experience. MCP governance expands the boundary. The control plane becomes the shared backend as rollout grows.
Start here · Cordum Edge
Put policy and approval in front of Claude Code shell commands, file changes, and governed MCP calls before side effects.
Developer path available today
Start with EdgeScale here · Cordum Platform
Move shared policy, approvals, workflows, and audit into the control plane when local adoption becomes a team requirement.
Platform backend for managed rollout
Explore the PlatformCoding agents and MCP clients can cross from suggestion into side effects in one tool call. A post-hoc log arrives too late.
Coding agents can run kubectl, Terraform, Git, and deployment commands with the same credentials as the developer.
A useful tool call can also write files, change policy, or touch production state unless identity and approval travel with it.
Finding a risky action after execution is evidence of what happened, not a way to prevent the damage.
Start at the coding-agent boundary, expand across MCP calls, and centralize the same decision model for production agent jobs.
Cordum Edge evaluates Claude Code shell and file actions at the hook boundary.
Gateway authentication, tenant scope, and the opt-in MCP policy gate sit before tools/call.
The platform centralizes policy and approval when local adoption grows into a shared fleet.
The same decision pattern follows an action from intent through policy, approval, execution, and redacted evidence.
Claude Code, an MCP client, or a production agent describes the intended action.
Identity, tenant, target, risk, and policy context are checked before execution.
The exact action is held until an authorized reviewer approves or rejects it.
Only an allowed or correctly approved action continues to its execution path.
Decision context, hashes, and approval references stay available for review.
$ cordumctl edge claude -- --print "prepare the production deploy" action kubectl apply -f deploy/prod.yaml policy REQUIRE_APPROVAL execution held before side effects evidence redacted descriptor + action hash
No anonymous-customer totals, invented benchmarks, or maturity shortcuts. Follow the source, docs, and explicit rollout boundary.
Available from source
Gateway, Safety Kernel, approvals, workflows, MCP server, CLI, and dashboard live in the public core repository.
Verify the surfaceDeveloper path available
The wrapper, hook, local agentd, Gateway evaluation, approvals, and redacted evidence path are documented today.
Verify the surfaceBuilt-in surface available
Cordum tools, resources, transports, tenant checks, and approval-aware mutations are implemented; per-tool policy is opt-in.
Verify the surfaceCustomer-managed today
Cordum is self-hosted. Fleet enforcement requires endpoint, identity, and deployment controls; support commitments belong in the order form.
Verify the surfacePractical guides and technical analysis for teams putting policy, approvals, and audit evidence in front of agent actions.
Choose the next step
Start with the Claude Code action boundary. Expand to MCP governance. Bring the same policy and approval model into the platform when your rollout becomes shared infrastructure.
Explore the PlatformGet release notes and technical updates on Edge, MCP governance, and the Cordum platform.
No spam. Unsubscribe anytime.