Agentbeam
IT & endpoint management

Beam for IT teams

Your people have AI on their laptops. Beam gives you a per-machine record of what that AI did — commands, file changes, tool and MCP calls, endpoints — stored locally and readable when someone asks.

It sits beside your existing endpoint tooling, and it observes rather than enforces.

An IT administrator reviewing AI coding agent activity records collected from managed developer laptops

What a rollout actually involves

Everything below is verifiable on one machine before you touch a second one.

  • Footprint

    One local process, loopback only

    The collector binds to 127.0.0.1:4319 and writes locally. No kernel extension, no browser extension, no OS surveillance to review.

  • Deployment

    A scripted per-machine setup

    A hook merged into settings plus a local service. Scriptable, but there is no signed Jamf, Kandji or Intune package today.

  • Coexistence

    Sits beside your EDR, not in front of it

    Beam watches the layer endpoint tooling cannot see: tool calls, MCP servers and skill files. It intercepts nothing at the OS level.

  • Portability

    Formats your pipeline already reads

    OTLP/HTTP JSON in, redacted NDJSON out. Nothing is forwarded automatically, so the data path is only what you build.

  • Supply chain

    Pre-run review of skills and MCP servers

    Eleven heuristic patterns plus a version-pin check, run before someone connects a file to production credentials.

  • Support

    An answer when someone asks what happened

    Flagged actions keep the triggering event as evidence, so a ticket closes with a record instead of a recollection.

What the security questionnaire will ask

Data location
The endpoint only — directories 0700, files 0600
Network listeners
One, on 127.0.0.1:4319
Outbound telemetry
None by default; no analytics, no third-party scripts
Secret handling
Known credential formats redacted before persistence
Retention per machine
Latest 10,000 events and 500 scan reports
Failure mode
Capture failures print to stderr and never halt the tool
MDM package
None — Jamf, Kandji and Intune are not supported
Central console
None — pairing is per-machine today
Enforcement
None — observe and alert only in v1

Why this lands on IT's desk

  • By 2028 (Gartner prediction)

    A quarter of enterprise breaches tied to AI agent abuse

    Gartner also puts spend on securing AI near $4.8 billion in 2027. Endpoint owners inherit most of that question.

  • July 2025

    An assistant update shipped an attacker's instructions

    A prompt injected through a pull request reached v1.84.0 of the Amazon Q extension. Software-update review does not cover instruction-layer risk.

  • September 2025

    A malicious MCP server reached an estimated 300 organizations

    postmark-mcp v1.0.16 added a silent BCC to an attacker address, on 1,643 total downloads. People install these without a procurement step.

A low-friction rollout

  1. 01

    Prove it on your own machine

    Run the collector, pair the app with its printed token, import a sample record. The token stays in browser memory, not in a URL.

  2. 02

    Pilot with a willing team

    Hooks are merged deliberately, so nothing changes on a laptop without an action someone took on purpose.

  3. 03

    Decide what to standardize

    Use two weeks of real activity to write policy grounded in what your AI does.

Answering the surveillance objection honestly

Beam is built so you can say precisely what it does — and what it cannot do.

Beam does

  • Record what the AI did: commands, file paths, tool and MCP calls, hostnames
  • Keep every record on the user's own machine, credentials redacted before write
  • Scan skill files and MCP configs someone is about to trust
  • Leave data in portable formats, so moving it off the endpoint is deliberate

Beam does not

  • Monitor the person: no keystroke logging, screen capture or browser extension
  • Send anything to a vendor, an analytics service or a central console
  • Deploy through Jamf, Kandji or Intune, or manage a fleet centrally
  • Capture activity from sources you have not instrumented
  • Block commands, gate approvals or enforce policy in v1

Questions IT asks first

Can we deploy Beam through Jamf, Kandji or Intune?

Not as a packaged deployment today. Pairing is designed for local single-machine use, and fleet management, SSO and database-backed teams are documented as future work. Setup is scriptable per machine — enough for a pilot, not a managed rollout.

Will people see this as surveillance?

Only if you describe it badly. Beam records what the AI did, not what the person did: no keystroke logging, no screen capture, no browser extension. Data stays in local files on their own machine, and nothing is forwarded automatically.

Does it conflict with our EDR or endpoint agent?

It should not. Beam is a userspace process on loopback that receives events a hook sends it. No kernel extension, no OS-level interception — and it covers the AI layer endpoint tooling has no visibility into.

What happens if the collector is down or misconfigured?

Work carries on. The hook sends a bounded request and emits no allow or deny response, so nothing waits on a verdict. The cost of a failure is a gap in the record, not a blocked person.

Start with one machine and a two-week pilot

Find out what AI is doing on your endpoints before you write the standard — with a record you can show the person it came from.

Set up Beam