Skip to main content

Getting Started with Swif's Agentic Security for Enterprise

Overview

If your organization already uses Swif for device management, you can enable Agentic Security directly from your existing Swif workspace — no separate sign-up required. Agentic Security gives your team visibility into AI agent activity across your managed devices, with real-time event streaming, risk classification, and audit logging.

What Is Agentic Security?

Agentic Security is a monitoring and security tool that helps you keep track of AI agent activity on your devices. It provides:

  • Real-time event streaming — See AI agent actions as they happen across your fleet.

  • Action risk classification — Every agent action is automatically tagged as Safe, Risky, or Danger based on what it does (e.g., reading a file is safe, executing a command is risky, deleting a file is danger).

  • Audit logging — Maintain a complete record of AI agent behavior for compliance and review.

  • Sensitive data redaction — API keys, passwords, and credentials are automatically detected and hidden before they appear in your logs.

What You'll Need

  • An active Swif enterprise workspace with admin access

  • A computer running Mac, Windows or Linux.

  • About 5 minutes

Supported Platforms

Platform

Installer Type

Windows

Executable (run as Administrator)

macOS

Signed/notarized zip archive

Linux x64

Binary with permission setup

Linux arm64

Binary with permission setup


Installing Agentic Security

Step 1: Access Agentic Security from Your Dashboard

Log in to your Swif workspace (app.swif.ai or app.eu.swif.ai). On your Home Dashboard, you'll see an Install Agentic Security card. Alternatively, you can access it through the FTUX Setup Guide.

Bulk Deployment via Swif MDM (Recommended)

For organizations using Swif MDM, you can now deploy Agentic Security in bulk across your entire fleet. This method ensures comprehensive coverage without manual installation on every device.

  • Monitoring Gap Detection: A dynamic info alert, "Agentic Security Monitoring Gap Detected," will appear at the top of the Devices page if any managed devices are missing the agent.

  • Configure Policies: Click Configure Policies from the alert to open the Agentic Security Deployment Policies modal.

  • Platform-Specific Policies: You can configure or add devices to the following policy types:

    • APPLE_AGENTIC_SECURITY_POLICY: For macOS 12.0+ devices.

    • WINDOWS_AGENTIC_SECURITY_POLICY: For Windows 10+ devices.

    • LINUX_AGENTIC_SECURITY_POLICY: For Linux devices.

  • Review Missing Devices: Click Review Devices within the deployment modal to see a detailed list of all managed devices currently lacking the Agentic Security agent.

  • Auto-Hide Logic: The monitoring gap alert will automatically hide once 100% agent coverage is achieved across your organization.

Manual Install Recommendations

If you prefer to send individual instructions, you can still use the Review Devices action from the Agentic Security page to email OS-specific setup guides directly to device owners.

Step 2: Download and Install the Agentic Security Agent

(For manual or BYOD enrollments)

  1. Click Setup Agentic Security from the dashboard card or Setup Guide.

  2. Select the appropriate installer for your OS (Windows, macOS, or Linux).

  3. Run the platform-specific installer as an Administrator (Windows) or with execute permissions (macOS/Linux).

Step 3: Enable Monitoring Policies

After installation, configure your monitoring policies from the Configuration tab in your device details:

  • Swif Agentic Security Logging Policy: Enables audit logging for AI agent activity.

  • Swif OpenClaw Config Tools Policy: Enables monitoring of configuration and tool usage.

Step 4: Monitor AI Agent Activity

Once Agentic Security is installed and policies are enabled, you can monitor AI agent activity from the Agentic Security tab in your device details. From here you can:

  • Stream events in real time — Watch AI agent actions as they happen on managed devices.

  • Filter activity — Filter events by subsystem (agent, gateway, hooks, browser, etc.), risk level, and time range.

  • Review risk classifications — Every action is tagged as Safe, Risky, or Danger so you can focus on what matters.

  • View device details — See encryption status, OS version, and last connected time.


CLI Agent Privilege Restriction & Root Protection

To prevent AI agents from accidentally or maliciously modifying system configurations, Swif Agentic Security automatically enforces least-privilege execution rules for supported CLI agents (such as openclaw).

Key Protection Capabilities

  • Automatic Sudo & Root Blocking: Once enrolled, the agent restricts users and scripts from executing CLI agents under sudo, direct binary paths (e.g., /opt/homebrew/bin/openclaw), root shells (sudo -s), or preserved environments (sudo -E).

  • Uninterrupted Normal Execution: CLI agents continue to operate normally with standard user permissions, ensuring developer workflows remain smooth and uninterrupted.

  • Selective & Non-Disruptive: The restriction targets only monitored AI CLI tools. Unrelated standard system commands (e.g., sudo whoami, sudo cat /etc/hosts) remain unaffected.

  • Persistent Enforcement: Restriction rules persist across device reboots and survive binary updates to the CLI agent.

  • Multi-User Fleet Coverage: Protection applies automatically across all non-root user accounts on the managed device.

  • Security Audit Logging: Any attempt to invoke a restricted agent with sudo is immediately blocked with a permission error and logged locally (/usr/local/trustclaw/) as well as in the Swif web application activity stream.


Removing the Agentic Security Agent

If you need to stop monitoring a device without deleting it:

  1. Open the Agentic Security device list.

  2. Find the enrolled device and open its action menu.

  3. Click Remove Agentic Security Agent.

  4. Confirm in the modal (verify the device name/serial number).

  5. The device's Agent Status will change to Inactive.

Deleting a Agentic Security Device

To permanently remove a device from Agentic Security:

  1. Open the Agentic Security device list.

  2. Find the device and open its action menu.

  3. Click Delete Device.

  4. Confirm the deletion.

  5. The device will be removed from the list and will no longer appear in search or filter results.


Not an Enterprise Customer? Sign Up as a Consumer

If you're an individual user and don't have a Swif enterprise workspace, you can still use Agentic Security! Sign up for a free consumer account and get started in minutes.

The consumer onboarding walks you through creating an account, installing the agent, and enabling monitoring policies — all from a personal dashboard.


Frequently Asked Questions

Q: Which AI tools does Agentic Security monitor?

A: Agentic Security detects and monitors activity from OpenClaw CLI, OpenClaw Desktop App, Codex, and Claude.

Q: Is Agentic Security the same as the Swif MDM agent?

A: No. Agentic Security is a separate product focused on monitoring and securing AI agent activity. It does not replace enterprise MDM features like remote lock, wipe, or device fleet management.

Q: Is the setup step shared across my organization?

A: Yes. Once any user in your organization clicks Download Installer, the setup step is marked as completed for all users in the org.

Q: Can I skip the Agentic Security setup step?

A: Yes. The Agentic Security step in the Setup Guide is optional and does not block other onboarding steps.

Q: How is enterprise onboarding different from consumer?

A: Enterprise users access Agentic Security through their existing Swif workspace — no separate account creation is needed. Consumer users sign up independently at the Agentic Security registration page.

Q: Can I use Agentic Security on BYOD devices?

A: Yes. Agentic Security supports enrollment on both corporate-managed and personal (BYOD) devices through the Consumer portal.

Want me to publish this as a Confluence page, or would you prefer it exported to a different format?

Q: What's the difference between removing the agent and deleting the device?

A: Removing the agent sets the device to Inactive but keeps the device record. Deleting the device removes it entirely from Agentic Security.

Q: Can I deploy Agentic Security to all my managed devices at once?

A: Yes. Using the Bulk Deployment feature on the Devices page, you can assign platform-specific policies to all eligible macOS, Windows, and Linux devices simultaneously.

Q: What happens if a device is missing a policy?

A: The device will show a "Missing Policy" state in the Activity tab. You can click Create/Assign TC Logging Policy to resolve this immediately.

Q: Can developers run CLI agents like OpenClaw with root or sudo privileges?

A: No. Swif Agentic Security blocks CLI agents from running with sudo or within root shell sessions to prevent privilege escalation and unauthorized system-level changes. Developers can continue running the tools normally under their standard user account permissions.

Q: Does blocking sudo for AI agents interfere with other administrative commands?

A: No. The restriction specifically applies to monitored AI CLI binaries. All standard administrative and developer commands using sudo continue to work without interruption.

Q: Where can administrators see blocked privilege escalation attempts?

A: Blocked sudo execution attempts are recorded with timestamps and usernames in the device's local Swif logs (/usr/local/trustclaw/) and surfaced in the Activity tab within the Swif web console.

Need Help?

If you run into any issues during setup, reach out to our support team or check the Agentic Security documentation for detailed troubleshooting steps.


Did this answer your question?