Deploy to a fleet

The six steps to deploy DefenseClaw enterprise to managed Windows, Linux and macOS endpoints, from choosing a profile and agents to your MDM recipe, config, ensure and a ringed rollout.

This page is the short path through an enterprise deployment. Each step makes one decision and links to the page with the details. You need an MDM, configuration-management tool or administrator shell that runs commands as SYSTEM on Windows and as root on Linux and macOS. Terms such as profile, lifecycle and ensure are defined in Concepts.

Not sure enterprise deployment is what you need? Read Is this for you? first. To compare the open-source and enterprise editions feature by feature, see the support matrix.

1. Pick the profile

A managed deployment runs in one of two profiles, and each computer runs only one of them.

DetailStandaloneSecure Client
Choose it whenYou deploy with Intune or any other MDM, a package, configuration management or an administrator shellYou run Cisco Secure Client and want DefenseClaw as one of its modules
PlatformsWindows, Linux, macOSWindows, macOS
Who decides on each tool callThe local policy engine. Cisco AI Defense is added when you turn it on and store a keyCisco AI Defense only
NextContinue with step 2 on this pageSecure Client managed deployment

The rest of this page covers the standalone profile. On Windows and macOS the profile defaults to Secure Client, so set enterprise.profile: standalone in the config (Two profiles).

2. Pick the agents

Each agent you protect is a key under guardrail.connectors in the config. Nothing is protected until you list one. DefenseClaw protects each agent in one of three ways:

RouteAgentsWhat DefenseClaw writes
Machine policyClaude Code, Codex, Cursor, GitHub Copilot, and OpenCode with DefenseClaw's managed OpenCode pluginIts hooks in the vendor's administrator-owned policy files, which apply to every user of the computer
Per-userDevin, Antigravity, Hermes, Amp and Kiro, and OpenCode while the managed plugin is not in force. On Linux and macOS also OpenHands and OmniGentThe guardian writes the hook, or plugin, into each enrolled user's own agent config and repairs it
ACP guardKiro in an editor that starts it over ACPNothing per user: the editor runs Kiro through defenseclaw-gateway enterprise acp

OpenHands and OmniGent are refused on Windows. Which agent and OS combinations were verified in this release is in the enterprise route table. How to list agents, users and per-agent modes is in Choose the agents to protect and Plan a rollout.

3. Pick your MDM

Every recipe follows the same MDM contract and uses the scripts in packaging/mdm. Each card names what you push.

The MDM recipes are templates, checked by simulating each MDM's execution context; they have not been run in a live tenant. The release files they deliver:

OSRelease file
Windows x64DefenseClawSetup-Enterprise-Standalone-x64.exe
Linuxdefenseclaw-enterprise-<version>-linux-<arch>.deb or .rpm, or the payload archive defenseclaw-enterprise-<version>-linux-<arch>.tar.gz
macOS (Apple silicon)defenseclaw-enterprise-<version>-darwin-arm64.pkg

<arch> is amd64 or arm64. DefenseClawSetup-Enterprise-x64.exe, without -Standalone-, is the Secure Client Setup. Verify the release's signed checksums.txt once and pin each file by its SHA-256, as What you deliver shows.

4. Deliver the config and the AI Defense key

The config is one YAML file that only administrators can change. The lifecycle installs it at a fixed path:

OSInstalled config
WindowsC:\ProgramData\Cisco\DefenseClaw\etc\config.yaml
Linux/etc/defenseclaw/config.yaml
macOS/opt/cisco/defenseclaw/etc/config.yaml

Start from A minimal config, which protects Codex and Claude Code in observe mode. A first install on Windows needs a config. On Linux and macOS an install without one protects no agents. How each wrapper takes the config is in Deliver the config.

The Cisco AI Defense key is optional. It never goes in the config, an MDM script or a command line. Store it with enterprise secret set, from standard input or a file only administrators can change: after the install on Windows, and before or after it on Linux and macOS; see Deliver the AI Defense key and Cisco AI Defense key.

5. Run ensure and read the result

ensure is the one action your MDM runs. It installs when nothing is installed, upgrades when the version differs, repairs drift and applies a changed config. When the host already matches, it changes nothing and reports "noop": true, so it is safe on every check-in. The kit's wrappers print one result document per run and exit with one of these codes:

ResultWindowsLinux, macOSMDM action
Success, or nothing to do00Success
Failed. The change has already rolled back16031Read errors[].code
Another run or the package manager is busy161875Retry later
Invalid arguments, such as a first Windows install without a config16392Fix the assignment

For MDM detection, use the registry marker (Windows), the package database or pkg receipt for inventory, and detect.ps1 or detect.sh with the health option for health; see Detection. To check a host by hand:

sudo /opt/defenseclaw/bin/defenseclaw-gateway enterprise linux status --json
sudo /opt/defenseclaw/bin/defenseclaw-gateway enterprise linux verify --json
sudo /opt/cisco/defenseclaw/bin/defenseclaw-gateway enterprise macos status --json
sudo /opt/cisco/defenseclaw/bin/defenseclaw-gateway enterprise macos verify --json
# From an elevated PowerShell
$Cli = 'C:\Program Files\Cisco\DefenseClaw\bin\defenseclaw.exe'
& $Cli enterprise windows status --profile standalone --json
& $Cli enterprise windows verify --profile standalone --json

Read coverage_complete and security_complete in the result (Health fields). Every exit code is listed in Exit codes.

6. Pilot in observe mode, then expand in rings

Deploy a pilot ring with guardrail.mode: observe. Observe mode records every decision, including what DefenseClaw would have blocked, without blocking on policy verdicts. When the pilot is healthy and the decisions are reviewed, set guardrail.mode: action and deliver the config again. Then grow the deployment in rings (pilot, early, broad, everyone), moving on only when a ring is healthy.

Plan a rollout has a ring plan with sizes and exit criteria (Step 5), and covers choosing users, handling existing per-user installs and planning upgrades and rollback.

Next steps