CirvixGuides / Claude Code
Claude Code,
under policy.
Every tool call Claude Code attempts passes CIRVIX before it runs.
Install
npm install -g @cirvix_ai/agent-control
Init
cirvix init
Connect
cirvix runtime # starts the local enforcement endpoint# point Claude Code's HTTP tool transport at the local endpoint
Policy
# starter rules ship with init; add deny rules for credential pathscirvix policy check
Test — watch a decision
With Claude Code running under CIRVIX, ask it to read a credential file such as
~/.aws/credentials. The read is denied by policy before it happens, an audit event is written,
and the agent sees a structured denial instead of your secrets.
Verify
Run cirvix logs to see the decision record: action normalized, rule matched,
decision DENY, payload redacted. A legitimate workspace read shows PERMIT.
If both behave that way, Claude Code is under control.