Steerly sits between Claude Code, Codex, Cursor, Copilot, and Gemini — and your repository. Every agent action is classified, every risky command is gated, every PR ships with a security brief.
Steerly wraps the four places agents cause damage: the chat, the shell, the dependency tree, and the pull request.
Codex, Claude Code, Cursor, Copilot, Gemini CLI — chat, file context, tool events, and approvals in a single timeline. Built for teams who run more than one agent at once.
Three-way classification on every shell command an agent proposes. Reads, tests, and lints fly through. Deps, migrations, deploys ask first. Secret reads and history rewrites never make it out of the sandbox.
Every PR opened by an agent ships with a 0–100 risk score, a list of sensitive surfaces touched, mapped policy hits, and a checklist of what a human reviewer should still verify before merge.
Every chat turn, every tool call, every approval — append-only and exportable. Policy library covers the OWASP-shaped stuff plus AI-native risks like changes to AGENTS.md, CLAUDE.md, and MCP config.
A live snapshot of how Steerly would classify common agent actions on an SMB Node repo. You can override any rule per-repo or per-environment.
No agent rewrites. No waiting for your AppSec team to bless something. Plug Steerly into the four places your agents already live.
Pick the repos you want covered. Steerly reads PR diffs only — no full repo storage, no source code retention.
Drop our shim into Codex, Claude Code, Cursor, or any MCP-aware client. Sessions, tool events, and command attempts stream into the workbench.
Start from the default pack — auth approvals, deps review, secret block, migration rollback notes — then add anything specific to your stack.
You let the agent drive 80% of the time. You ship to prod from your laptop. You just want a soft floor under your worst day.
You have a CTO, no AppSec lead, and three different agents in active use. You need governance without buying a SOC.
Per-repo pricing scales with what you actually want covered. Unlimited developers on every plan.
Open the live workbench — every panel is real, every interaction wired up. No signup.