Agentbeam
Platform & security engineering

Beam for security teams

Your engineers use AI everywhere and no single system knows what it did. Beam normalizes the AI sources you instrument into one local record, flags risky actions with evidence, and scans skills and MCP configs before they are trusted.

Today it runs per-machine. Fleet management, SSO and enforcement are future work, not shipped.

A security engineer reviewing flagged AI agent actions from several developer machines in a single normalized activity log

What a pilot gives you

Scoped to v1 — every item below is verifiable on a machine this week.

  • Source-agnostic

    One schema across tools

    Claude Code hook payloads, OTLP/HTTP JSON logs and imported numbat records normalize into one event shape, ATT&CK tags preserved.

  • Evidence

    Flags you can adjudicate

    Credential exposure, destructive commands and privilege changes surfaced against the raw event — reviewable, not a score you must trust.

  • Supply chain

    Pre-run review of skills and MCP servers

    Eleven heuristic patterns plus a version-pin check, run before someone connects a file to real credentials.

  • Portable data

    Formats your pipeline already speaks

    OTLP/HTTP JSON in, redacted NDJSON out. No proprietary sink, no background forwarding to explain to a privacy review.

  • Data handling

    A short answer for the questionnaire

    Local files at 0700/0600, credential formats redacted before persistence, no analytics or telemetry by default.

  • Investigation

    An exportable case

    Event, scan and review files with SHA-256 hashes. Hashes establish internal consistency, not authenticity or completeness.

Numbers that frame the decision

Securing-AI spend, 2027 (Gartner)
≈$4.8B, up 68.7% over 2026
Enterprise breaches from agent abuse by 2028 (Gartner)
25%
Agentic-AI adopters with mature governance (Deloitte)
≈21%
Orgs reporting an AI-agent security incident
About 1 in 5
Beam retention, per machine
10,000 events / 500 reports
Beam enforcement today
None — observe and alert only
Fleet management, SSO, shared teams
Not shipped — future work

The failure modes you are underwriting

  • July 2025

    An agent deleted a production database during a code freeze

    Replit's agent removed records for 1,200+ executives and 1,190+ companies, then misreported it. Nobody could reconstruct the sequence afterwards.

  • September 2025

    A malicious MCP server reached an estimated 300 organizations

    postmark-mcp v1.0.16 added a silent BCC to an attacker address, on 1,643 total downloads. MCP supply-chain review is not theoretical.

  • 2025–2026

    Tool configuration is itself an attack surface

    CVE-2025-54135 showed a hosted prompt rewriting Cursor's config; Check Point disclosed hook injection and ANTHROPIC_BASE_URL exfiltration in Claude Code.

How teams pilot it

  1. 01

    Instrument a handful of machines

    Hooks are merged by hand, deliberately. Beam never installs or enforces a hook, so nothing changes without someone's action.

  2. 02

    Watch what your AI does for two weeks

    Find out which risky patterns your org actually produces before writing policy about them.

  3. 03

    Export a case and decide

    If enforcement is a hard requirement now, Beam is the wrong tool this quarter — that is stated on purpose.

Where Beam fits, and where it doesn't

Beam does

  • Give you one normalized record across the AI tools on a machine
  • Scan skills and MCP configs before someone connects them
  • Keep data local, redacted and in portable formats you move yourself
  • Support a pilot and an evidence-gathering exercise honestly

Beam does not

  • Deploy via Jamf, Kandji or Intune, or manage a fleet centrally
  • Provide SSO, shared dashboards or approval workflows
  • Block, gate or enforce policy on any AI action in v1
  • Forward to a SIEM, or replace an enterprise AI-security platform

Questions from security reviews

Can Beam enforce policy on developer machines today?

No. Beam v1 observes and alerts. The Claude Code hook emits no allow or deny response, and enforcement records imported from other tools are counted as skipped. Enforcement is on the roadmap; treating it as shipped would be a misrepresentation.

Can we deploy it across a fleet with MDM?

Not yet. Pairing is designed for local single-user testing, and fleet management, SSO, database-backed teams and approvals are documented as future work. Beam is a per-machine tool you can pilot, not a managed rollout.

What leaves the machine?

Nothing by default. The collector binds to 127.0.0.1:4319, writes local files at 0700/0600, redacts known credential formats before persistence, and the management app carries no analytics or third-party scripts. Exports happen when a person runs one.

How does Beam relate to numbat and other open-source monitors?

Beam is an independent implementation, not a fork, and it interoperates rather than competes: it imports numbat's normalized event and finding records with source references and ATT&CK tags intact, and accepts OTLP/HTTP JSON from anything else you run.

Pilot it on ten machines before you write the policy

Find out what your teams' AI actually does, with evidence you can read, before committing to a control you cannot yet enforce.

Set up Beam