Enterprise deployment
What DefenseClaw enterprise hardening is, which profile to choose, what runs on each endpoint, and what a standard user can and cannot change on Windows, Linux, and macOS.
A normal DefenseClaw install belongs to the person who runs the AI agent. That person can stop it, edit its policy, or remove its hooks. Enterprise deployment moves DefenseClaw out of their reach. An administrator or an MDM installs it as operating-system services. The services, the policy, and the program files belong to the administrator. The AI agent still runs in the user's session and its hooks still call DefenseClaw. But the user, and any agent that user runs, can no longer turn the protection off.
In the config this is deployment_mode: managed_enterprise
(managed_enterprise).
Two profiles
A managed deployment runs in one of two profiles. Pick the one that matches how you deploy software.
| Secure Client | Standalone | |
|---|---|---|
| Choose it when | You run Cisco Secure Client and want DefenseClaw as one of its modules | You deploy with Intune or any other MDM, a .deb, .rpm or .pkg package, configuration management, or an administrator shell |
| Platforms | Windows, macOS | Windows, Linux, macOS |
| Who decides on each tool call | Cisco AI Defense only. The local detectors are off | The local policy engine (rule packs, policy, CodeGuard). Cisco AI Defense is added when you turn it on and store an API key |
| If Cisco AI Defense is unreachable | The Secure Client posture applies | The local verdict stands |
| Documented in | Enterprise hardening and deployment | This section |
Rules that apply to both:
- One profile per computer. The two profiles use the same gateway port, and on Windows the same service names. Uninstall one before you install the other. The standalone lifecycle refuses to install over a Secure Client deployment.
- The profile is fixed at install. The config sets
enterprise.profile, and every service is started withDEFENSECLAW_ENTERPRISE_PROFILEset to the same value. If they disagree, the service refuses to start. To change profile, uninstall one and install the other. - The default depends on the OS. When neither is set, Windows and macOS
resolve to
secure_clientand Linux resolves tostandalone. Linux rejectssecure_client. For a standalone deployment on Windows or macOS, always setenterprise.profile: standalonein the config.
The rest of this section covers the standalone profile.
What runs where
Every endpoint runs the same four parts. The
gateway decides on each tool call and
runs as a restricted service account. The
guardian installs and repairs each
user's hooks. The enumerator finds the
users to protect. The sensor helper
answers a fixed set of privileged discovery questions for the gateway. The
hook (defenseclaw-hook) is an
administrator-owned program that the agent runs as the user.
The services and their identities on each OS:
| Part | Windows | Linux (systemd) | macOS (launchd) |
|---|---|---|---|
| Gateway | DefenseClawGateway, as NT SERVICE\DefenseClawGateway | defenseclaw-gateway.service, as the defenseclaw user with no capabilities. systemd holds its sockets (defenseclaw-gateway-api.socket, defenseclaw-gateway-hook.socket) | com.cisco.defenseclaw.gateway, as the hidden _defenseclaw user |
| Guardian | DefenseClawHookGuardian, LocalSystem | defenseclaw-hook-guardian.service, root with a bounded capability set | com.cisco.defenseclaw.hook-guardian, root |
| Enumerator | DefenseClawHookEnumerator, LocalSystem | defenseclaw-hook-enumerator.service, root with a bounded capability set | com.cisco.defenseclaw.hook-enumerator, root |
| Sensor helper | DefenseClawSensorHelper, LocalSystem | defenseclaw-sensor-helper.service, root | com.cisco.defenseclaw.sensor-helper, root |
| Applies a config change | Your MDM runs ensure again with the new config | defenseclaw-enterprise-apply.path runs ensure when the config, secrets or policies change | com.cisco.defenseclaw.apply does the same |
| Daily check | Your MDM runs detection or verify | defenseclaw-enterprise-verify.timer runs verify once a day | com.cisco.defenseclaw.verify runs verify once a day |
The guardian reconciles every minute and the enumerator runs every five
minutes on every OS. The gateway listens only on 127.0.0.1:18970. On Linux
and macOS, hooks and DefenseClaw's in-agent plugins reach the gateway only
through its local hook socket (/run/defenseclaw-hook/hook.sock,
/opt/cisco/defenseclaw/run/hook.sock), which tells the gateway each
caller's uid; there is no TCP fallback. On Windows they use the loopback
address with credentials bound to the user's SID.
The same parts mapped to the trust zones:
| Zone | Windows | Linux | macOS |
|---|---|---|---|
| Z1 Privileged services | Guardian, enumerator, sensor helper as LocalSystem | Guardian, enumerator, sensor helper as root | Guardian, enumerator, sensor helper as root |
| Z2 Restricted gateway | NT SERVICE\DefenseClawGateway | defenseclaw | _defenseclaw |
| Z3 Administrator-owned state | C:\Program Files\Cisco\DefenseClaw, C:\ProgramData\Cisco\DefenseClaw, C:\ProgramData\Cisco\DefenseClaw-HookRuntime. Vendor policy: %ProgramData%\OpenAI\Codex, %ProgramFiles%\ClaudeCode\managed-settings.d, %ProgramData%\Cursor, %ProgramData%\GitHub\Copilot\policy.d, %ProgramData%\opencode | /opt/defenseclaw, /etc/defenseclaw, /var/lib/defenseclaw-hook-guardian, /var/lib/defenseclaw-enterprise. Vendor policy: /etc/codex, /etc/claude-code, /etc/cursor, /etc/github-copilot, /etc/opencode | /opt/cisco/defenseclaw, /Library/Logs/Cisco/DefenseClaw. Vendor policy: /etc/codex, /Library/Application Support/ClaudeCode, /Library/Application Support/Cursor, /etc/github-copilot, /Library/Application Support/opencode |
| Z4 User session | The agent and defenseclaw-hook.exe | The agent and /opt/defenseclaw/bin/defenseclaw-hook | The agent and /opt/cisco/defenseclaw/bin/defenseclaw-hook |
Inside the Z3 folders, the gateway account writes only its own data, log and
socket folders (for example runtime). Everything else there is written by
administrators and DefenseClaw's privileged services.
The full layout of each OS is on its install page: Windows, Linux, macOS.
Who can change what
| Config | Policies | Secrets | Binaries and services | Per-user hook config | Vendor machine policy | Audit logs | |
|---|---|---|---|---|---|---|---|
| Administrator or MDM | Writes | Writes | Writes | Installs, upgrades, removes | Not needed: the guardian manages DefenseClaw's entries | Writes. DefenseClaw changes only its own entries | Reads |
| DefenseClaw services | Gateway reads | Gateway reads | Gateway reads the one it needs | Run them | Guardian writes DefenseClaw's entries, as the user | Linux and macOS: the lifecycle writes DefenseClaw's own entries. Windows: the lifecycle writes Codex's; the guardian writes Claude Code's, Cursor's, Copilot's and OpenCode's. See Who writes machine policy | Gateway writes |
| Standard user | No write | No write | No access | Runs the hook; cannot stop, change or replace a service | Owns the files; the guardian repairs its entries | Agent reads it; no write | No access |
| AI agent a prompt can steer | Same as the user it runs as | Same as the user | Same as the user | Same as the user | Same as the user; the foreign-hook guard handles hooks it adds | Same as the user | Same as the user |
DefenseClaw does not defend a computer from its own administrators. An agent
that runs with unrestricted sudo or administrator rights is an
administrator.
What a standard user cannot do
- Stop, disable, or reconfigure a DefenseClaw service, or replace one of its programs.
- Edit the config, policies, secrets, target manifest or authorization ledger, or read the Cisco AI Defense key.
- Remove DefenseClaw's hooks from vendor machine policy, or tell the agent to skip them where DefenseClaw sets the vendor's managed-hooks-only lock. Which agents get the lock on which OS is on Machine policy.
- Keep a user or project hook that could rewrite a tool call after DefenseClaw checked it, for the agents the foreign-hook guard covers.
- Pose as the gateway. The hook sends nothing until the operating system shows that the listener is the DefenseClaw service (peer verification).
- Run a second, per-user DefenseClaw. On a managed computer the per-user
installer,
defenseclaw upgrade, and the per-user gateway refuse to run.
A user can still edit or delete files they own, such as a per-user hook registration. The guardian repairs DefenseClaw's entries on its next pass. Vendor machine policy has no such window. The threat model has the full list and the risks that remain.
Supported platforms and agents
| OS | Requirements |
|---|---|
| Windows | 64-bit Windows on x64 (releases ship no ARM64 build). A stable, machine-wide PowerShell 7 from Microsoft's installer, which the standalone lifecycle uses. An elevated administrator or SYSTEM context |
| Linux | systemd 239 or later. The defenseclaw-enterprise package is built as .deb and .rpm for x86-64 and arm64; a tarball is also published. Run as root |
| macOS | macOS 13.0 or later on Apple silicon, for the defenseclaw-enterprise-<version>-darwin-arm64.pkg package. Run as root |
Details are under Requirements on each install page: Windows, Linux, macOS.
DefenseClaw protects each agent in one of three ways:
| How | Agents | Notes |
|---|---|---|
| Machine policy | Codex, Claude Code, Cursor, GitHub Copilot, and OpenCode through DefenseClaw's managed OpenCode plugin | DefenseClaw's hooks sit in the vendor's administrator-owned policy files, which apply to every user of the computer |
| Per-user | Devin, Antigravity, Hermes, Amp. On Linux and macOS also OpenHands, OmniGent and Kiro | The guardian writes DefenseClaw's hook, or plugin, into each enrolled user's own agent config and repairs it |
| Through the ACP guard | Kiro on Windows | Run it through defenseclaw-gateway enterprise acp. See ACP guard |
OpenClaw and ZeptoClaw are not supported in enterprise deployments. OpenHands and OmniGent are refused on Windows. The per-OS details, including which vendor locks DefenseClaw sets, are on Machine policy. Agent versions and setup are on each connector page.
A minimal config
The administrator config is one YAML file. The example below protects Codex
and Claude Code in observe mode, so policy verdicts do not block yet. The
Linux and macOS tabs install as written with ensure --config. They leave
guardrail.rule_pack_dir out, so the gateway uses a rule pack you put in
<policy_dir>/guardrail/default, and otherwise the default pack that ships
with DefenseClaw. If you create that folder after installing, run ensure:
it notices the new pack and restarts the gateway with it.
config_version: 8
deployment_mode: managed_enterprise
data_dir: /var/lib/defenseclaw # must be exactly this path
policy_dir: /etc/defenseclaw/policies
enterprise:
profile: standalone
gateway:
api_bind: 127.0.0.1
api_port: 18970
guardrail:
enabled: true
mode: observe # observe | action
connectors:
codex: {}
claudecode: {}config_version: 8
deployment_mode: managed_enterprise
data_dir: /opt/cisco/defenseclaw/runtime # must be exactly this path
policy_dir: /opt/cisco/defenseclaw/etc/policies
enterprise:
profile: standalone
gateway:
api_bind: 127.0.0.1
api_port: 18970
guardrail:
enabled: true
mode: observe # observe | action
connectors:
codex: {}
claudecode: {}config_version: 8
deployment_mode: managed_enterprise
# Leave data_dir unset: the services use C:\ProgramData\Cisco\DefenseClaw\runtime.
enterprise:
profile: standalone
gateway:
api_bind: 127.0.0.1
api_port: 18970
guardrail:
enabled: true
rule_pack_dir: "" # use the built-in rule packs
mode: observe # observe | action
connectors:
codex: {}
claudecode: {}Four things to know before you deploy it:
- Nothing is protected until you list agents. Each key under
guardrail.connectorsturns on one agent. On Linux and macOS, the config the lifecycle writes when you supply none lists no agents, so it protects nothing. On Windows, install andensurerequire a config. On Linux and macOS, naming Codex, Claude Code, Cursor, GitHub Copilot or OpenCode anywhere underguardrail.connectors(even withenabled: false) or underenterprise.machine_policy.connectorsmakes the lifecycle publish DefenseClaw's hook in that agent's machine policy; on Windows that rule applies to Copilot and OpenCode. To leave an agent unprotected, leave it out of both maps or set itsownership: "off". See Choose the agents to protect. - Observe mode does not block on policy verdicts. In
observemode DefenseClaw records each decision, including what it would have blocked. Switchguardrail.modetoactionto enforce. The deployment's own checks apply in both modes: a tool call is still refused while an unapproved foreign hook is present (withforeign_hooks: remove), or when the user is not enrolled where enrollment is enforced. - The data directory is fixed. On Linux and macOS the lifecycle rejects
any other
data_dir. On Windows, adata_dirother than the runtime directory is rejected too. - Tell enrollment about unusual layouts (Linux and macOS). Users are
enrolled from homes under
/homeand/var/home(Linux) or/Users(macOS), and agent CLIs are found in the usual install locations. If homes live elsewhere, such as/srv/home, list the parent folders underenterprise.enrollment.home_roots; if agents are installed under an administrator prefix, such as an npm--prefixof/opt/tools, list it underenterprise.enrollment.agent_prefixes. See Enrollment.
Where the file goes on each OS, every enterprise.* setting, and the proxy
settings are on Configuration.
The optional Cisco AI Defense key never goes in the config: store it after the install, as Cisco AI Defense key shows.
Next steps
Plan a rollout
Choose agents and users, pilot in observe mode, handle existing per-user installs, and expand in rings.
Threat model
Trust zones, how each boundary is protected, and the risks that remain.
Windows
Install the four standalone services with the Setup program or PowerShell 7.
Linux
Install the systemd units with the deb or rpm package, or from a payload directory.
macOS
Install the LaunchDaemons and the hidden service user from the pkg.
Install with an MDM
The MDM contract and recipes for Intune, Jamf, Kandji, Workspace ONE, Configuration Manager, and Linux configuration management.
Configure
Where the config lives, how to choose agents, and every enterprise setting.
Operate
Check status and health, read logs and events, and verify machine policy.
Enterprise hardening and deployment
Provision DefenseClaw as a managed operating-system service, understand its trust boundaries, and continuously repair per-user AI-agent hooks.
Enterprise concepts
A glossary of the terms used in DefenseClaw's enterprise deployment docs, from profiles and the lifecycle to enrollment, machine policy, health fields, and the Windows, Linux, and macOS security terms.